US7478157B2 - System, method, and business methods for enforcing privacy preferences on personal-data exchanges across a network - Google Patents

System, method, and business methods for enforcing privacy preferences on personal-data exchanges across a network Download PDF

Info

Publication number
US7478157B2
US7478157B2 US10/046,034 US4603401A US7478157B2 US 7478157 B2 US7478157 B2 US 7478157B2 US 4603401 A US4603401 A US 4603401A US 7478157 B2 US7478157 B2 US 7478157B2
Authority
US
United States
Prior art keywords
data
subject
privacy
specifying
constraints
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active, expires
Application number
US10/046,034
Other versions
US20030088520A1 (en
Inventor
Kathryn A. Bohrer
Catherine A. Chess
Robert L. Hoch
John Karat
Dogan Kesdogan
Xuan Liu
Edith G. Schonberg
Moninder Singh
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
International Business Machines Corp
Original Assignee
International Business Machines Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by International Business Machines Corp filed Critical International Business Machines Corp
Priority to US10/046,034 priority Critical patent/US7478157B2/en
Assigned to INTERNATIONAL BUSINESS MACHINES CORPORATION reassignment INTERNATIONAL BUSINESS MACHINES CORPORATION ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS). Assignors: BOHRER, KATHRYN A., LIU, XUAN, CHESS, CATHERINE A., HOCH, ROBERT L., KARAT, JOHN, KESDOGAN, DOGAN, SCHONBERG, EDITH G., SINGH, MONINDER
Publication of US20030088520A1 publication Critical patent/US20030088520A1/en
Application granted granted Critical
Publication of US7478157B2 publication Critical patent/US7478157B2/en
Active legal-status Critical Current
Adjusted expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00Administration; Management
    • G06Q10/10Office automation; Time management
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/383Anonymous user system

Definitions

  • This invention relates generally to privacy for information handling across a network. More specifically, the invention relates to methods, systems and business methods to enforce privacy preferences on exchanges of personal data across a network.
  • Various Personal e-Wallet and Data Vault products and services provide the ability to store, and sometimes share, personal information. Often, tools are provided, usually as a browser plug-in, to allow users to drag and drop from their stored data onto web forms while browsing. In some cases the web site's privacy policy is compared to the consumer's policy preferences and warnings are issued when there is a mismatch. Privacy policies are often based on the Platform for Privacy Preferences or P3P standard. Examples of such products include Microsoft's Internet Explorer and Passport service, Novell's digitalMe, Lumeria's SuperProfile and ZeroKnowledge's Freedom.
  • Microsoft's Hailstorm service is an extension to its Passport service that provides data subject's a repository to store their personal data, and allows the data subject to grant permission to third party services and applications to access that data.
  • the data subject has to give explicit access to third parties to access the data, and limited amount of privacy control is provided in that the data subject can specify who can access the data, for what purpose and revoke access or give access for a limited period of time.
  • Enterprise Policy development tools help an enterprise develop their privacy policy and publish it on their web sites. These tools generally help in identifying personal information in databases and web pages, and help in creating a policy statement. Examples of such tools include the PentaSafe VigiEntPolicy Center, the IBM P3P policy editor, and Idcide Privacy Wall Site Analyzer. Policies are expressed as free form text and/or P3P XML documents.
  • Enterprise Policy Enforcing Private Data Management products are designed for enterprises to control or monitor access to personal data stored within the enterprise, according to the enterprise's privacy policies. Some of the products focus on support for privacy regulations, some provide both the data repositories and the policy enforcement, while some provide only policy enforcement. Some of the products are out-sourced services while others are technology used to implement in-house solutions. These products are generally access control systems enhanced to allow more permissions specifically for different usages that are covered by the enterprise privacy policies. Permissions are associated with different authenticated users or lists of users that request access to data. Examples of such products include Privaseek Persona p-CRM, PrivacyRight TrustFilter Privacy and Permission Management for the Enterprise, Tivoli SecureWay Privacy Manager, and Idcide Privacy Wall Site Monitor.
  • the Customer Profile Exchange Specification or CPExchange is a standard that defines how a P3P policy can be associated with personal data in an XML message. This policy applies to the data being provided by one party to another, and provides a way for an enterprise to include the applicable privacy policy with personal data exchanged between applications or between organizations.
  • Enterprise Privacy-enhancing Data Manipulation tools and technologies are used to eliminate privacy issues by transforming data so it is no longer personally identifiable, or to operate on data and produce results that are not personally identifiable. Data mining for trend analysis or targeted marketing can often benefit from these products. These products may be offered as out-sourced services or technology for in-house solutions. Examples are Privacy Infrastructure Inc. AsPrin, IBM Intelligent Miner Family, and ETI*Extract. All of these except the first one are not privacy specific, but are general tools for data analysis and transformation.
  • a data subject's personal data is distributed across many enterprises and repositories, and it is not practical to expect all this data to be collected in one central repository, or to be owned by one enterprise or even the data subject.
  • Each enterprise owns some of the personal data they generate about a data subject, such as financial information in a bank, or health information in a hospital.
  • a data subject's financial data may be held/owned by several enterprises such as his bank, credit card providers and broker, while his employment data is held by his employer and his health information is held by his doctors and health insurance providers.
  • the data subject has various other personal data, such as current phone numbers, addresses, clothing preferences, and a wide range of other preferences. None of the current products deal with allowing a data subject to express privacy preferences for controlling access to their personal data that is distributed across multiple enterprises and repositories. While enterprises often offer data subjects an “opt-out” policy by which the data subject can explicitly choose to allow or disallow the enterprise from sharing his data, this is an extremely limiting kind of privacy control since it imposes the policy of the enterprise on the data subject, with little or no capability to express policies specific to each data subject (other than the opt-out/opt-in option to some portion of the enterprise's policy). However, data subjects want complete freedom to specify their own privacy preferences (and not the data owner's or data holder's) on how their personal data is handled, regardless of where that data is stored or who owns that data.
  • a data subject should be able to express complex privacy preferences that include who can access data, what set of data or type of data they can access, for what purpose the access is granted, how long the data can be retained, who the data can be shared with and for what purposes, and whether the data must subsequently be accessible to the data subject.
  • current systems may allow specification of a policy to be associated with the “current purpose”, but there is no way to apriori state a policy for different business transactions like “placing an order”, “requesting information”, “applying for a loan”, etc. for the prescribed purposes.
  • current systems will apply the same policy to all data exchanges with a given data requester.
  • data subjects often need much more flexibility than is allowed by these current systems.
  • a data subject may choose to allow access to different sets of data, with different policies on usage and sharing, for different requests made by the same data requester, based on the context of the request.
  • Another feature which is missing in current products is the capability to enforce a data subject's policy even when the data subject is not directly involved. This is necessary if a data subject's privacy policy is to be followed in all business processing.
  • Most of the current personal privacy enforcement products only assist the data subject in filling in a form on a web page with stored data, or in comparing the data subject's privacy preferences with a web page privacy policy and providing warnings to the data subject. This requires the data subject to be online and actively involved in providing the data that is being requested. Others always require a data subject to give explicit approval once to a requester for accessing certain data owned by the data-subject, with subsequent requests being, possibly, handled automatically.
  • a data subject may want to setup privacy preference policies which can allow fully automatic release of data, even without knowing about the requester or the request itself. Moreover, one would like to do so even for data that is held/owned by third parties. For example, a data subject may decide to allow access to non-identifying employment data such as work experience, salary range, etc., to anyone who requests such data as long as the privacy policy governing use, retention etc., match those of the data subject. That would enable any interested party to access such data about the data subject automatically via an automatic privacy policy matching process and send the data subject job listings in which the data subject may have interest.
  • a data subject may allow access to certain, non-identifiable financial data such as employment status and salary range, thus enabling interested financial institutions to automatically access such data and send solicitations for credit cards/loan requests to the data subjects.
  • Current products lack this feature as well.
  • An exemplary embodiment of the present invention includes a method to enforce privacy preferences on exchanges of personal data of a data-subject.
  • the method comprises the steps of: specifying one or more data-subject authorization rule sets, the data-subject authorization rule set having one or more subject constraints on one or more data-subject data, receiving a request message from a requester, the request message having one or more requests for one or more of the data-subject data pertaining to the a subject, and a requester privacy statement for each of the respective data-subject data requested, comparing the requester privacy statement to the subject constraints, and releasing the data-subject data in a response message to the requester only if the subject constraints are satisfied.
  • the requester privacy statement includes purpose, retention, recipient, and access information, wherein the purpose information specifies the purpose for which the requested data is acquired, the retention information specifies a retention policy for the requested data, the recipient information specifies the recipients of the requested data, and the access information specifies whether the requested data should be accessible to the data-subject after the data has been released.
  • FIG. 1 is a block diagram of one preferred embodiment of present invention.
  • FIG. 2 is a block diagram of a rule data structure.
  • FIG. 3 is a block diagram of a privacy preference portion of the rule structure.
  • FIG. 4A is a block diagram of a data-request message structure.
  • FIG. 4B is a block diagram of a data-response message structure
  • FIG. 5 is a flow chart of the request process.
  • FIG. 6 is a flow chart of the data requester privacy, policy and data subject privacy preference rule matching process
  • FIG. 7 is a flow chart of a gather and filtering process.
  • FIG. 8 is a block diagram of a method of doing business with the current invention wherein subject data is distributed across multiple enterprises, and a trusted third party is used as a data subject's personal data service to handle and process requests for data owned by the data subject as well as by the various enterprises (third party data suppliers).
  • FIG. 9 is a block diagram of a method of doing business with the current invention wherein subject data is distributed across multiple enterprises, with each enterprise holding enterprise-specific data and privacy preferences of the data subject, and accepting and processing requests for data held by it directly from interested data requesters where an optional trusted third party may be used as data subject's personal data service to handle requests for data that is owned by the data subject.
  • the invention involves the use of computers and networks. It is not limited as to the type of computers used, and not limited as to the type of networks used. Various implementation methods may be used for the present invention.
  • the invention involves information that is communicated between computers; this information could be in hypertext markup language (HTML), or extensible markup language (XML), e-mail, or some other language or protocol could be used.
  • HTML hypertext markup language
  • XML extensible markup language
  • e-mail or some other language or protocol could be used.
  • FIG. 1 is a block diagram illustrating an embodiment of the present invention. This embodiment supports the enforcement of privacy preferences in data exchanges according to authorization checks based on the privacy preferences specified by a data subject with the privacy policies of a data requester.
  • the Data Subject 100 can use a web browser 101 to setup one or more profiles via communication links 103 , such as HTTP requests. Similarly, the Data Subject can use a web browser to set up one or more privacy policies by specifying authorization rules describing to whom, and under what conditions, the data can be released via communication links 104 , such as HTTP requests.
  • a Data Requester 105 can use a web browser 106 or some other computer programs 107 to send requests for data 109 as well as receive replies 110 to that request along with any returned data.
  • Each request for data is also accompanied by the data requester's privacy policies describing the intended usages of the requested data. Such policies are stored by the requester in a policy database 108 .
  • the system To facilitate the requests from a Data Subject to setup data profiles and privacy policies, as well as requests for data from Data Requesters, the system must provide several different functionalities, including the ability to setup profiles, define authorization rules and privacy controls, send and handle requests for data, authenticate requesters, authorize release of data based on authorization rules and privacy policy matching and release data, etc.
  • the embodiment provides these functionalities using a series of software and hardware components 111 to 124 , including a manual authorization engine 111 , a policy authorization engine 112 , a profile updater 113 , an interaction history agent 114 , a profile publisher 115 , a profile responder 116 , a privacy policy publisher 117 , a manual profile responder 118 , a logger 119 , an authentication engine 120 , a profile manager 121 , a policy manager 122 , a profile database 123 and a policy database 124 .
  • the Profile Manager 121 maintains basic profile information and provides programming interfaces for creating, querying, modifying and deleting profile information.
  • the Policy Manager 122 maintains basic policy information and provides programming interfaces for creating, querying, modifying and deleting policy information.
  • the profiles are stored in a Profile Database 123 while the policies are stored in a Policy Database 124 .
  • the Policy Authorization Engine 112 performs automatic authorization for release of requested data based on authorization rules including information about privacy policy information associated with data, templates and request types, as well as users authorized to access the data
  • Privacy policies can be different for different groups of requesters and may also be specified at a data class, data instance, template or request level. Definitions of privacy policies can also include policies on profile data held by third-parties. As such, it also handles requests for authorization for release of personal data held by a third-party, just as if the data was held directly by the current system.
  • the Policy authorization engine also supports the data subject by providing the data requester with an explicit one time authorization for a particular request type as an alternative to privacy policy matching against data and requester class/group.
  • the Authentication Engine 120 authenticates requesters of profile information, authorization or updates.
  • the Profile Responder 116 receives requests for profile information along with privacy statements on how the data will be used. It uses the Authentication engine 120 to authenticate the requester and uses the Policy authorization engine to check the authorization and privacy policies. It may need to check return from the Policy Authorization engine to see if external authorization is needed on any of the requested data, and handle requests to those external authorization sources. Similarly, it must recognize need for manual authorization and invoke the Manual Authorization Engine 111 , if needed. It uses the Profile and Policy Managers to get only the subset of information that is allowed by the policy checks and uses the Logger component to record the request and the response. It also checks data returned by the query on the Policy Authorization engine 112 to see if some data needs to be obtained from an external source, and handles requests to those external sources.
  • the Manual Authorization Engine 111 provides the ability to perform manual authorization of a portion of the requested data. Invoked by the Profile Responder (or possibly the Policy Engine) to initiate a manual authorization, it sends an e-mail or otherwise notifies the data provider of the need for manual authorization.
  • the data subject can use various computer programs 102 , such as e-mail software, to respond to such a request.
  • the Profile Updater 113 receives requests to create, delete, or modify profile information. Like the Profile Responder, this component must authenticate the requester, log the request and response, check for authorization to make the profile update, and update the profile information.
  • the Interaction History Agent 114 provides support for user specification of what actions should be intercepted. This could be stored in the form of rules or explicit action types. An intermediary or proxy can then be used to intercept the desired online actions and record them as additional profile data.
  • the Profile Publisher 115 and the Privacy Policy Publisher 117 provide the user interfaces for specifying authorization information, privacy policies, profile data and templates. They can use the Profile and Policy Managers for reading and writing the information, or could go more indirectly through the Profile Updater and Profile Responder components.
  • the Manual Profile Responder 118 provides the user interfaces for gathering missing data in order to fulfill a profile data request. Invoked by the Profile Responder (or possibly the Profile Manager) to initiate entry of missing requested profile data. Sends an e-mail or otherwise notifies data provider for missing data entry. The e-mail can provide an easy way to launch a browser-based user interface to specify the needed data.
  • the Logger 119 supports logging of requests to and responses by the system, and uses the Profile Manager to make any updates to the profile.
  • the Data Subject sets up data profiles and privacy policies using the Profile Publisher and the Privacy Policy Publisher. These would be stored in the Profile and Policy database, respectively.
  • a Data Requester sends a request for data describing the data desired along with privacy policies describing the intended usage. The request is handled by the Profile Responder which uses the Authentication engine to verify the identity of the requester and the Policy Authorization engine to check the authority of the requester to access the requested data by using authorization rules and privacy policies, possibly invoking the Manual Authorization engine (to get manual authorizations).
  • FIG. 1 While the system described in FIG. 1 is capable of executing the processes described herein, this system is only one example of such a system. Those skilled in the art will appreciate that many other system designs are capable of performing the processes described herein.
  • FIG. 2 is a diagram of the data structure of an Authorization Rule 201 .
  • Each Authorization Rule 201 consists of four subelements: an Authorization Dataset 202 , a Privacy Preference Rule 203 , an Access List 204 , and an Authorization Action 217 .
  • an Authorization Rule a data subject defines a mapping from the first three subelements to a result action specified by the Authorization Action.
  • an Authorization Rule declares that for a specified Authorization Dataset, the specified Privacy Preference Rule is applied for the specified Access List allow the specified Authorization Action.
  • the Authorization Dataset in a rule contains the data items that can be released according to the rule.
  • Each authorization data set can be either a View Level 205 or a data type/object defined by a Class 209 , a Property 210 , an Instance 211 , or a combination of these.
  • a Class defines an object type (such as contact information), a Property defines a field within a Class (e.g. telephone number), and an Instance refers to a specific object (such as Joe's home-address).
  • the combination of these may specify a data item constrained by all specified subelements. For example, specifying both class and property for a data item confines it to the property within the specified class.
  • a data subject can categorize his/her personal data into multiple View Levels (layers) so that the data in each View Level have the same privacy preference, access and authorization constraints, whereas data in different View Levels have different constraints.
  • a View Level consists of a View Name 206 , a Level Rank 208 , and one or more Viewlevel Items 207 .
  • the View Name specifies which view this View Level belongs to, and the Level Rank declares which privacy level this View Level is confined with.
  • the Level Rank can be used as a filter to retrieve the possible View Levels.
  • Each Viewlevel item is further specified by a class, an instance, a property or a combination of them.
  • Rules specified for a given View Level are inherited by View Levels of lower Level Ranks, unless overridden by rules specified by rules for the lower View Level, either for the entire level or for some class, instance, property or combination thereof of the dataset at the lower ranked View Level.
  • the invention enables automated data exchange with considerable privacy protection for the data subject. All critical, highly personal data may be placed in one layer with very stringent privacy and access controls, while least sensitive data may be placed in a layer with the least amount of controls, with other data occupying intermediate layers. This, combined with the ability to associate rules with specific classes, instances, and properties of data gives the data subject a wide degree of flexibility in specifying different privacy and access controls for different categories of data, different types of requests, different classes of requesters, etc.
  • the Access List in a rule declares who can access the specified data set upon Privacy Preference matching.
  • Each Access List contains one or more authorized Party 212 , which can be a user 213 , a group 214 , a token 215 , or “all” requesters 216 .
  • a user refers to a registered data requester, who has a userid and authentication data.
  • a group contains multiple users, while one user may belong to multiple groups.
  • a data subject can define one authorization rule for one or more groups of users who are then granted access to the data for the same privacy preference rules
  • a token provides a way to allow controlled access to the data by limiting, for example, the number of times the data may be accessed. Any data requester in possession of the token is allowed access to the data as long as the token is valid.
  • a token may also be issued to a data requester to enable access to data that is held by a third party.
  • the token is then presented by the data requester to the third-party which uses it to identify the requester as well as the data to which the requester is authorized. If the authorized party has the special value “all”, then access is granted to all requesters of the data for whom the privacy preference rules match. In such cases, and anyone can access the data as long as the privacy policies of the requester match those of the data subject.
  • the Authorization Action 217 declares which one of the actions should be taken if this rule is matched.
  • the action “grant” 218 means that the request should be granted if this rule is matched, the action “notify” 219 specifies that data subject should be notified when the request is granted, and the action “get consent” 220 specifies that special consent should be obtained before the request can be granted.
  • the Privacy Preference Rule in an Authorization Rule specifies the privacy preference and action control that the data users in the access list have to satisfy in order to access the data.
  • FIG. 3 is an expansion of the Privacy Preference Rule 203 in FIG. 2 . It explains the data structure for specifying a Privacy Preference Rule for the data requesters in the Access List to access the data in the Authorization Dataset.
  • the Privacy Preference Rule 301 in an Authorization Rule contains two declarations: data subject's privacy preferences and access actions allowed by the data subject.
  • the Privacy Preference 302 specifies why and how the data can be accessed in terms of the P3P standards. It includes several statements: Purpose 304 , Retention 305 , Recipient 306 , and Access 307 . The system may define other statements 308 based on a specific application domain requirements.
  • Purpose specifies the purposes for which the data can be acquired and processed. According to P3P, there are 13 sub-elements allowed in declaring Purpose.
  • the privacy policy can contain one or more of the following:
  • Retention refers to the kind of retention policy applied to the data. According to P3P, there are 5 possible sub-elements in declaring Retention.
  • the system may need to add/delete sub-elements for application purposes.
  • a data subject can specify the retention using one of the following sub-elements.
  • Recipient specifies the legal entity, or domain, beyond the requester where the data may be distributed. There are 6 possible sub-elements. The system may need to add/delete sub-elements for application purposes. A data subject can specify the retention using one of the following sub-elements.
  • Access in the privacy preference describes whether the data in the corresponding authorization data set should be accessible by the data subject after the data has been released. Boolean values (true/false) are used to represent the access requirement flag. Different from the Purpose and Retention, Access declares the access capability that the requestor must provide to the data subject for his/her own data.
  • Action control 303 specifies whether an access action is allowed. It contains several action permissions, each of which is represented by a boolean value.
  • Action “create” 310 declares whether the data user can create the data, update 311 declares whether the data user can modify the data, and delete 312 declares whether the data user can delete the data. Additional actions 313 may be added according to application requirements.
  • FIG. 4 a is a block diagram of a Data Request Structure.
  • a request for data is sent from a Data Requester to the Profile Responder, and shown in FIG. 1 .
  • a data request identifies a data subject, and includes a request for specific items of data from the data subject. The data request also specifies how it will use the data in the request, in the form of privacy declarations.
  • a data request consists of three parts: a Privacy Header 401 , a Query 402 , and Request Items 403 .
  • a Privacy Header consists of the name of the requester, the name of the responder, and a list of privacy declarations. Each privacy declaration has the structure of a Privacy Preference, as described in FIG. 3 .
  • the Query consists of sufficient information to uniquely identify the data subject from whom the data is desired. When the query is applied to the Profile Database ( FIG. 1 ), it retrieves a data subject.
  • the list of Request Items identifies the specific data items being requested.
  • Each request item consists of two parts: a reference 404 to one of the privacy declarations in the Privacy Header 401 and the name of one or more data items.
  • the meaning of this pairing is the following: for each requested data item, if the request recipient (data subject) supplies this data item to the requester, then the requester promises to enforce the associated privacy declaration for that data item.
  • a request item can consist of a single privacy declaration reference 404 and multiple data item names.
  • FIG. 4 b is a block diagram of a Data Response Structure.
  • a data response is sent from the Profile Responder of the system to the data requester, in response to a data request described in FIG. 4 a .
  • a data response is either a denial, if the request cannot be fulfilled, or the subset of specific data items which were requested and authorized, along with associated privacy declarations representing the data subject's privacy preferences.
  • a data response consists of two parts: a Privacy Header 410 and Response Items 411 .
  • a Privacy Header consists of the name of the responder, the name of the requester, and a list of privacy declarations. Each privacy declaration has the structure of a Privacy Preference, as described in FIG. 3 .
  • the list of Response Items is empty if the request cannot be fulfilled, either because the data subject profile does not exist, data requester is not authorized to access the data, or the privacy declarations in the request header do not match the privacy preferences associated with the subject profile. If the request can be fulfilled by the response system, then the list of response item is not empty.
  • Each response item consists of two parts: a reference 412 to one of the privacy declarations in the Privacy Header and a data response.
  • a data response is a name-value pair from the profile of the data subject, corresponding to a requested data item.
  • a response item can consist of a single privacy declaration reference and multiple response items.
  • FIG. 5 is a flow diagram of the Request Process, whereby the system receives a data request structure, processes it, and returns a data response structure to the requester.
  • the Profile Responder receives the data request 501 .
  • the first step that the responder performs is to authenticate the requester 502 . Authentication is the process of guaranteeing that the requester is who they say they are, and can be carried out in several ways, including the use of a userid and password, or a cookie, etc. If the authentication is not successful, then the response is returned with an empty response item list 505 . If authentication succeeds, then the data request is passed to the Policy Authorization Engine which retrieves all Authorization Rules of the data subject specified in the request 503 .
  • the data subject is identified from the query in the request, which is applied to the profile database. Once the data subject is identified, all of the authorization rules are retrieved for him/her from the policy database. If there are no authorization rules for the data subject, the Profile Responder returns a response with an empty response item list. Otherwise, the next step is to examine the Access List of each of these retrieved authorization rules 504 . For each access list, if the requester is not found in the access list, then the authorization rule is discarded. The requester is in the access list if the requester is either a user in the list or a user in a group which is in the list, or if the access list explicitly authorizes “all” requesters.
  • the Policy Authorization Engine next compares the privacy declarations in the request with the Privacy Preference Rules in the authorization rules for each profile data item name in the request item 506 . For each data item name in the query and in the request item list, the Policy Authorization Engine retrieves any privacy preferences from the authorization rules. It then performs the Policy-Preference matching process (see FIG. 6 ) for each data item. For each application of this matching process, the result is deny 507 or authorize 508 , 509 , or 510 . If the result is deny, then the data item is not included in the list of data items to be returned in the response 511 .
  • the data item is included in the response item list 512 . Additionally, the authorization rule may require the data subject to be notified 513 or the consent of the data subject be obtained 514 . After each data item name is processed, the next data item is retrieved for processing 515 . When the entire request list has been processed, the data to be returned is gathered 516 , the response structure is constructed and returned to the requester by the Profile Responder 517 . If any of the data items have been denied, the Profile Responder may return an empty list to the requester, for more privacy security for the data subject.
  • FIG. 6 is a simple flow chart of the Data Requester Privacy Policy and Data Subject Privacy Preference Rule Matching process.
  • the Privacy Preference Rule is specified by the Data Subject in the Authorization Rules as explained in FIG. 2 and FIG. 3 , while the Data Requester's Privacy Policy is declared by the data requester as a part of the data request ( FIG. 4 a ). Since both the privacy preference rule and the privacy policy are based on the P3P standard, the matching process is to check the matching for each element.
  • Purpose checking 601 checks the purpose privacy statements. Both the privacy policy as well as the privacy preference rule purposes may contain one or more subelements. If the subelements declared in the privacy policy is a subset of the subelements specified in data subject's privacy preference rule, the purpose checking is successful and the matching algorithm proceeds to the retention statement check 602 .
  • the Retention statement can be declared by one of the five subelements: ⁇ no-retention/>, ⁇ stated-purpose/>, ⁇ legal-requirement/>, ⁇ business-practices/> and ⁇ indefinitely/>. These subelements express different privacy levels, some of them are more restricted than others.
  • the subelement ⁇ no-retention/> has the most restrictive privacy level, and the subelement ( ⁇ indefinitely/>) is the least restricted.
  • ⁇ stated-purpose/> is more restricted than ⁇ legal-requirement/> and ⁇ business-practices/>, both of which are more restricted than ⁇ indefinitely/>.
  • the retention statement check proceeds according to this particular order.
  • Recipient checking 603 then checks the matching for recipient statement.
  • the recipient statement can be declared by one of the six subelements: ⁇ ours/>, ⁇ delivery>, ⁇ same/>, ⁇ other-recipient/>, ⁇ unrelated/>, and ⁇ public/>. These subelements express different privacy levels with ⁇ ours/> being the most restrictive, followed by ⁇ same/> and ⁇ delivery/>, then ⁇ other-recipient/> and ⁇ unrelated/>, with ⁇ public> being the least restrictive.
  • the matching process is successful if the recipient declared in the privacy policy is not less restricted than the recipient specified in the privacy preference rule.
  • Access checking 604 checks the matching for the requirements of the capability for a data subject to access the data after a data requester acquires the data. The access checking is successful if the access requirement of the data subject is satisfied by the access statement declared in the policy. Finally, Action control checking 605 checks if the actions requested by the data requester are allowed according to the action control specified in data subject's privacy preference rule. If no action control is specified, read is assumed and allowed. This is done by simple checking the corresponding Boolean tag of a specific action in the preference. If all the checking is successful, the request is authorized 606 , otherwise any failure along the matching process causes the request to be denied 607 .
  • FIG. 7 is a flow diagram of a routine that enables a gather and filtering process carried out to collect data to be returned to a data requester.
  • the process of matching the privacy policy of the data requester with the authorization rules specified for the requested data by the data subject results in a list of such data items that are to be returned to the data requester.
  • This flow diagram described the various steps that could be potentially involved in the gathering of such data.
  • the system examines the list of data items to be returned. If all the data is available locally on the system 701 , the system collects it 702 , prepares the reply structure 710 and sends it to the data requester 711 .
  • the system collects whatever data is locally available 703 . It then checks if some of the data items have missing values 704 . If yes, it contacts the data subject and retrieves the required data items from him/her 705 . In step 706 , the system determines if the data that is not available locally is available from third parties. If it is available, then the system retrieves the data from the third parties holding the data in step 707 . It then filters the data again in step 708 by matching the data returned by the third parties with the request of the data requester and the privacy policies and authorization rules of the data subject. This ensures that only that data is returned that is allowed.
  • step 709 the system authorizes the release of any data that is held by third parties but is not available for release by the system itself (must be directly requested from the third parties by the data requester).
  • the system then prepares a reply for the data requester 710 by collecting together all the data (locally collected or retrieved from third parties) as well as information about the data authorized to be released by third parties. It then sends this reply to the data requester 711 .
  • a data requester can get data held not only by the system locally but also held by third parties, either via collection by the system itself or directly from third parties after authorization by the system.
  • the process ensures that only that data is released, or authorized to be released, for which the data requester is authorized and for which the requesters privacy policies match that of the data subject.
  • FIG. 8 describes one method of doing business with the current invention wherein the subject data is distributed across multiple enterprises, and a trusted third party is used as a data subject's personal data service to handle and process requests for data owned by the data subject as well as by the various enterprises (third party data suppliers).
  • a trusted third party acts as a Personal Data Service (PDS) 804 for the Data Subject 800 , and provides a server-based, possibly distributed, environment for hosting the data that is owned by the data subject himself.
  • the data subject may choose to store all such data in the PDS profile repository 806 , or store some of it on his own personal machine profile repository 802 .
  • PDS Personal Data Service
  • the data subject may store his privacy policies entirely on the PDS policy repository 807 , or distribute them between the PDS repository and his personal system policy repository 803 . These policies may cover both data that is owned by the data subject and resides either on the PDS or on the data subject's personal system, as well as data that is owned by, and resides with, third party Data Suppliers 814 in their profile repositories 818 .
  • the PDS hosts all components 805 (described in FIG. 1 ) for creating and managing profiles, publishing privacy and authorization preferences, handling and responding to requests, authenticating requesters and privacy policy matching as well as releasing or authorizing release of data.
  • the data subject's personal system also hosts several software components 801 , including local copies of the profile and policy publishers and managers to help publish and manage the data and policies that reside on the data subject's personal system, as well as e-mail and web browser software to help publish profiles and policies on the PDS, provide manual authorization and missing data responses 812 as well as handle notifications 811 from the PDS.
  • a Data Requester 808 must also have a minimal set of software components 809 such as a local policy publisher and manager for the data requester's privacy policies stored in its policy repository 810 .
  • each Data Supplier 814 which owns and stores part of the data subject's data must also host some of the software components 817 for managing the data subject's data they store in their profile repository 818 as well as for handling data requests from, and sending responses to, the PDS.
  • the PDS acts as an agent of the Data Subject.
  • a Data Subject would register with the PDS and store his Profile as well as Privacy Policies with the PDS.
  • the Data Subject may choose to keep part of the Profile and Privacy policies on his own personal system as well.
  • the profile and privacy policies stored with the PDS will include information on where missing information is available, either from the Data Subject's personal system or from third-party Data Suppliers.
  • Data Requesters would also be required to register with the PDS.
  • a Data Requester desiring access to some data about a Data subject then sends a request 813 to the PDS identifying the Data Subject as well as the data requested, along with its own privacy policies on how the requested data would be used.
  • the PDS uses the various software components 805 , as described earlier in FIG. 1 and elsewhere, the PDS then authenticates the requester and matches the privacy policies of the requester with the authorization rules/privacy preference rules specified by the Data Subject. If manual authorization is needed for some data, the PDS requests such authorization 811 from the Data subject.
  • the PDS carries out a gather and filtering process, as described in FIG. 7 , to collect the data to be returned to the Data Requester.
  • the PDS collects all data that is locally available, and sends a request to the Data Subject to get any data that is available only from the personal system of the Data Subject. If any requested data is available from third-party Data suppliers, 814 , the PDS sends requests 815 for such data to the Data Suppliers.
  • the profile responder 817 run by a data supplier handles such requests from the PDS, and sends the data back to the PDS.
  • the PDS just sends the Data Supplier an authorization to release the data directly to the Data Requester when so requested. Once all the data has been collected, or authorized to be released, the PDS sends it to the Data Requester along with information about any third party data suppliers to contact for remaining data. The Data Requester may then get this data directly from the Data Suppliers.
  • the PDS acts as a trusted agent for the Data Subject, and relieves the subject of the responsibility of hosting the data and policies as well as handling and processing requests of data from Data Requesters. Moreover, it can function as a fully automatic system, requiring no intervention by the data subject once the profile and privacy policies have been set, in most circumstances. From a Data Requester's point of view, this method is beneficial as well since it has to send one request for data to the PDS to get data that is owned by the Data Subject as well as by other Data Suppliers. Finally, this method provides an independent service provider the ability to act as a PDS, and provide the server platform and hosting service as a fee-based service for Data Requesters and Data Subjects.
  • FIG. 9 describes a method of doing business with the current invention wherein subject data is distributed across multiple enterprises, with each enterprise holding enterprise-specific data and privacy preferences of the data subject, and accepting and processing requests for data held by it directly from interested data requesters.
  • every enterprise that holds any data belonging to the Data Subject 900 runs all privacy-software components 905 (described in FIG. 1 ) for creating and managing privacy and authorization preferences, handling and responding to requests, authenticating requesters, performing privacy policy matching as well as releasing data.
  • These include all third-party Data Suppliers 910 as well as Data Requesters 908 , the two being interchangeable in that any enterprise can be a requester of data, or a supplier of data, at different times.
  • each such enterprise has several other components 909 , including a repository of its own privacy policies describing how it uses any requested data along with a local policy publisher and manager for managing such policies, as well as a repository of Data Subject's privacy policies governing the release of the Data Subject's data that is owned and held by the enterprise.
  • Each enterprise is thus responsible for storing a Data subject's privacy policies as well as handling and processing any requests made for such data by any Data Requesters.
  • a Data Subject publishes 911 his privacy preference policies directly with each potential enterprise that holds any data on the Data Subject.
  • a Data Requester 908 too directly sends its data request 913 , along with its privacy policy, to the Data Supplier which holds the requested data.
  • the Data Supplier 910 then uses the various privacy-software components 905 , as described in FIG.
  • the Data Supplier requests such authorization 912 from the Data Subject.
  • his personal system also hosts several software components 901 , such e-mail and web browser.
  • the Data Subject may still choose to use a trusted third-party as his Personal Data Service (PDS) 904 to manage access to personal data that is owned by the Data Subject.
  • PDS Personal Data Service
  • the PDS runs all the privacy-software components 905 to help it receive and process requests for the data owned by the Data subject, as well as a repository of such data 906 and privacy-preferences governing access to such data 907 .
  • the Data Subject may choose to keep some of the data, as well as policies, on repositories 902 and 903 on his personal system, along with privacy-software components to manage them 901 .
  • a Data Requester who needs data that is owned and held by the Data subject would then send such a request 913 to the PDS, which would process the request and respond with the data, with optional contact 911 / 912 with the Data Subject's system.
  • This method of doing business has several features of benefit to all the parties involved. Since every enterprise runs the various privacy-software components, and stores the Data Subject's privacy preferences governing the data owned/stored by the enterprise, it is easy for enterprises to maintain and share data amongst them, according to the privacy preferences of the Data Subject. Moreover, it also enables enterprises to show the Data Subject's the data they have about him. Finally, the Data Subject can still choose to use a PDS to act as his trusted agent for hosting the data that he owns as well as handling and processing requests for that data from Data Requesters.

Abstract

An exemplary embodiment of the present invention includes a method to enforce privacy preferences on exchanges of personal data of a data-subject. The method comprises the steps of: specifying data-subject authorization rule sets having subject constraints, receiving a request message from a requester and a requester privacy statement, comparing the requester privacy statement to the subject constraints, and releasing the data-subject data in a response message to the requester only if the subject constraints are satisfied. The requester privacy statement includes purpose, retention, recipient, and access information, wherein the purpose information specifies the purpose for which the requested data is acquired, the retention information specifies a retention policy for the requested data, the recipient information specifies the recipients of the requested data, and the access information specifies whether the requested data should be accessing to the data-subject after the data has been released.

Description

FIELD OF THE INVENTION
This invention relates generally to privacy for information handling across a network. More specifically, the invention relates to methods, systems and business methods to enforce privacy preferences on exchanges of personal data across a network.
BACKGROUND
Many approaches to handling privacy preferences during personal data exchanges have been proposed in the past. These approaches can generally be divided into several product and technology areas: personal e-wallet/data vault products, enterprise specific e-wallet/data vault products, personal privacy enforcing agents, enterprise policy development, enterprise policy enforcing private data management, and enterprise privacy-enhancing data manipulation. The function of each of these is described briefly in the subsequent sections.
Various Personal e-Wallet and Data Vault products and services provide the ability to store, and sometimes share, personal information. Often, tools are provided, usually as a browser plug-in, to allow users to drag and drop from their stored data onto web forms while browsing. In some cases the web site's privacy policy is compared to the consumer's policy preferences and warnings are issued when there is a mismatch. Privacy policies are often based on the Platform for Privacy Preferences or P3P standard. Examples of such products include Microsoft's Internet Explorer and Passport service, Novell's digitalMe, Lumeria's SuperProfile and ZeroKnowledge's Freedom. Microsoft's Hailstorm service is an extension to its Passport service that provides data subject's a repository to store their personal data, and allows the data subject to grant permission to third party services and applications to access that data. The data subject has to give explicit access to third parties to access the data, and limited amount of privacy control is provided in that the data subject can specify who can access the data, for what purpose and revoke access or give access for a limited period of time.
Current Personal Policy Enforcing products are designed to support a user's privacy policy preferences. A few of the e-wallet/data vault products provide some of this functionality, but the products listed here focus on allowing a complex privacy policy to be represented and checked against either a web site's privacy policy or a data requester's privacy policy. These products use a P3P Preference Exchange Language or APPEL as a language to express what P3P policies are acceptable. Agents retrieve the P3P policies associated with a web site and compare them to the APPEL rules. Mismatches result in warnings to the user. The user then takes whatever action they deem appropriate, such as not filling out the web site form. Examples of these agents are the AT&T Privacy Minder and the IBM Privacy Assistant.
Enterprise Policy development tools help an enterprise develop their privacy policy and publish it on their web sites. These tools generally help in identifying personal information in databases and web pages, and help in creating a policy statement. Examples of such tools include the PentaSafe VigiEntPolicy Center, the IBM P3P policy editor, and Idcide Privacy Wall Site Analyzer. Policies are expressed as free form text and/or P3P XML documents.
Enterprise Policy Enforcing Private Data Management products are designed for enterprises to control or monitor access to personal data stored within the enterprise, according to the enterprise's privacy policies. Some of the products focus on support for privacy regulations, some provide both the data repositories and the policy enforcement, while some provide only policy enforcement. Some of the products are out-sourced services while others are technology used to implement in-house solutions. These products are generally access control systems enhanced to allow more permissions specifically for different usages that are covered by the enterprise privacy policies. Permissions are associated with different authenticated users or lists of users that request access to data. Examples of such products include Privaseek Persona p-CRM, PrivacyRight TrustFilter Privacy and Permission Management for the Enterprise, Tivoli SecureWay Privacy Manager, and Idcide Privacy Wall Site Monitor.
Standards have also been developed that promote the exchange of data over the internet as well as through non-internet messaging systems. The Customer Profile Exchange Specification or CPExchange is a standard that defines how a P3P policy can be associated with personal data in an XML message. This policy applies to the data being provided by one party to another, and provides a way for an enterprise to include the applicable privacy policy with personal data exchanged between applications or between organizations.
Enterprise Privacy-enhancing Data Manipulation tools and technologies are used to eliminate privacy issues by transforming data so it is no longer personally identifiable, or to operate on data and produce results that are not personally identifiable. Data mining for trend analysis or targeted marketing can often benefit from these products. These products may be offered as out-sourced services or technology for in-house solutions. Examples are Privacy Infrastructure Inc. AsPrin, IBM Intelligent Miner Family, and ETI*Extract. All of these except the first one are not privacy specific, but are general tools for data analysis and transformation.
However, the above-mentioned examples have several limitations which are addressed by the current invention. These limitations are discussed in detail in the following paragraphs.
One major limitation is that current products assume that a data subject owns all personal data and/or all this data is available in one central repository or enterprise. However, a data subject's personal data is distributed across many enterprises and repositories, and it is not practical to expect all this data to be collected in one central repository, or to be owned by one enterprise or even the data subject. Each enterprise owns some of the personal data they generate about a data subject, such as financial information in a bank, or health information in a hospital. Thus, a data subject's financial data may be held/owned by several enterprises such as his bank, credit card providers and broker, while his employment data is held by his employer and his health information is held by his doctors and health insurance providers. At the same time, the data subject has various other personal data, such as current phone numbers, addresses, clothing preferences, and a wide range of other preferences. None of the current products deal with allowing a data subject to express privacy preferences for controlling access to their personal data that is distributed across multiple enterprises and repositories. While enterprises often offer data subjects an “opt-out” policy by which the data subject can explicitly choose to allow or disallow the enterprise from sharing his data, this is an extremely limiting kind of privacy control since it imposes the policy of the enterprise on the data subject, with little or no capability to express policies specific to each data subject (other than the opt-out/opt-in option to some portion of the enterprise's policy). However, data subjects want complete freedom to specify their own privacy preferences (and not the data owner's or data holder's) on how their personal data is handled, regardless of where that data is stored or who owns that data.
Moreover, the current products that do store a data subject's preferences do so in a limited way, often based on P3P privacy declarations. These are aimed at use in a situation made clear to the data subject by the context of the request. However, a data subject should be able to express complex privacy preferences that include who can access data, what set of data or type of data they can access, for what purpose the access is granted, how long the data can be retained, who the data can be shared with and for what purposes, and whether the data must subsequently be accessible to the data subject. For example, current systems may allow specification of a policy to be associated with the “current purpose”, but there is no way to apriori state a policy for different business transactions like “placing an order”, “requesting information”, “applying for a loan”, etc. for the prescribed purposes. Moreover, current systems will apply the same policy to all data exchanges with a given data requester. However, data subjects often need much more flexibility than is allowed by these current systems. For example, a data subject may choose to allow access to different sets of data, with different policies on usage and sharing, for different requests made by the same data requester, based on the context of the request.
Another feature which is missing in current products is the capability to enforce a data subject's policy even when the data subject is not directly involved. This is necessary if a data subject's privacy policy is to be followed in all business processing. Most of the current personal privacy enforcement products only assist the data subject in filling in a form on a web page with stored data, or in comparing the data subject's privacy preferences with a web page privacy policy and providing warnings to the data subject. This requires the data subject to be online and actively involved in providing the data that is being requested. Others always require a data subject to give explicit approval once to a requester for accessing certain data owned by the data-subject, with subsequent requests being, possibly, handled automatically. However, a data subject may want to setup privacy preference policies which can allow fully automatic release of data, even without knowing about the requester or the request itself. Moreover, one would like to do so even for data that is held/owned by third parties. For example, a data subject may decide to allow access to non-identifying employment data such as work experience, salary range, etc., to anyone who requests such data as long as the privacy policy governing use, retention etc., match those of the data subject. That would enable any interested party to access such data about the data subject automatically via an automatic privacy policy matching process and send the data subject job listings in which the data subject may have interest. Similarly, a data subject may allow access to certain, non-identifiable financial data such as employment status and salary range, thus enabling interested financial institutions to automatically access such data and send solicitations for credit cards/loan requests to the data subjects. Current products lack this feature as well.
Yet another limitation of current products is the inability for data subjects to be able to easily express complex policies on a large set of personal data, in a way that is applicable regardless of the specific representation and data model used by enterprises that store this data. This is important since, as point out above, a data subject's data will be distributed across multiple enterprises and repositories. One way to facilitate this is by supporting an abstract data model, supporting a data type hierarchy, and by grouping data into levels within multiple views. Policies can then be applied at different granularities, to either views or levels within views, with the views themselves described by using both data types and data instances, such as, for example, all phone numbers or just the data subject's cell phone number. Current products do not have this kind of flexibility.
These limitations, along with public concern regarding privacy of personal data, make it highly desirable for systems and methods for enforcing privacy preferences on personal data exchanges across networks.
BRIEF SUMMARY
An exemplary embodiment of the present invention includes a method to enforce privacy preferences on exchanges of personal data of a data-subject. The method comprises the steps of: specifying one or more data-subject authorization rule sets, the data-subject authorization rule set having one or more subject constraints on one or more data-subject data, receiving a request message from a requester, the request message having one or more requests for one or more of the data-subject data pertaining to the a subject, and a requester privacy statement for each of the respective data-subject data requested, comparing the requester privacy statement to the subject constraints, and releasing the data-subject data in a response message to the requester only if the subject constraints are satisfied. The requester privacy statement includes purpose, retention, recipient, and access information, wherein the purpose information specifies the purpose for which the requested data is acquired, the retention information specifies a retention policy for the requested data, the recipient information specifies the recipients of the requested data, and the access information specifies whether the requested data should be accessible to the data-subject after the data has been released.
BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS
The foregoing and other objects, aspects, and advantages will be better understood from the following non limiting detailed description of preferred embodiments of the invention with reference to the drawings that include the following:
FIG. 1 is a block diagram of one preferred embodiment of present invention.
FIG. 2 is a block diagram of a rule data structure.
FIG. 3 is a block diagram of a privacy preference portion of the rule structure.
FIG. 4A is a block diagram of a data-request message structure.
FIG. 4B is a block diagram of a data-response message structure
FIG. 5 is a flow chart of the request process.
FIG. 6 is a flow chart of the data requester privacy, policy and data subject privacy preference rule matching process
FIG. 7 is a flow chart of a gather and filtering process.
FIG. 8 is a block diagram of a method of doing business with the current invention wherein subject data is distributed across multiple enterprises, and a trusted third party is used as a data subject's personal data service to handle and process requests for data owned by the data subject as well as by the various enterprises (third party data suppliers).
FIG. 9 is a block diagram of a method of doing business with the current invention wherein subject data is distributed across multiple enterprises, with each enterprise holding enterprise-specific data and privacy preferences of the data subject, and accepting and processing requests for data held by it directly from interested data requesters where an optional trusted third party may be used as data subject's personal data service to handle requests for data that is owned by the data subject.
DETAILED DESCRIPTION
The invention involves the use of computers and networks. It is not limited as to the type of computers used, and not limited as to the type of networks used. Various implementation methods may be used for the present invention. The invention involves information that is communicated between computers; this information could be in hypertext markup language (HTML), or extensible markup language (XML), e-mail, or some other language or protocol could be used.
FIG. 1 is a block diagram illustrating an embodiment of the present invention. This embodiment supports the enforcement of privacy preferences in data exchanges according to authorization checks based on the privacy preferences specified by a data subject with the privacy policies of a data requester.
The Data Subject 100 can use a web browser 101 to setup one or more profiles via communication links 103, such as HTTP requests. Similarly, the Data Subject can use a web browser to set up one or more privacy policies by specifying authorization rules describing to whom, and under what conditions, the data can be released via communication links 104, such as HTTP requests.
Similarly, a Data Requester 105 can use a web browser 106 or some other computer programs 107 to send requests for data 109 as well as receive replies 110 to that request along with any returned data. Each request for data is also accompanied by the data requester's privacy policies describing the intended usages of the requested data. Such policies are stored by the requester in a policy database 108.
To facilitate the requests from a Data Subject to setup data profiles and privacy policies, as well as requests for data from Data Requesters, the system must provide several different functionalities, including the ability to setup profiles, define authorization rules and privacy controls, send and handle requests for data, authenticate requesters, authorize release of data based on authorization rules and privacy policy matching and release data, etc. The embodiment provides these functionalities using a series of software and hardware components 111 to 124, including a manual authorization engine 111, a policy authorization engine 112, a profile updater 113, an interaction history agent 114, a profile publisher 115, a profile responder 116, a privacy policy publisher 117, a manual profile responder 118, a logger 119, an authentication engine 120, a profile manager 121, a policy manager 122, a profile database 123 and a policy database 124. The Profile Manager 121 maintains basic profile information and provides programming interfaces for creating, querying, modifying and deleting profile information. Similarly, the Policy Manager 122 maintains basic policy information and provides programming interfaces for creating, querying, modifying and deleting policy information. The profiles are stored in a Profile Database 123 while the policies are stored in a Policy Database 124.
The Policy Authorization Engine 112 performs automatic authorization for release of requested data based on authorization rules including information about privacy policy information associated with data, templates and request types, as well as users authorized to access the data Privacy policies can be different for different groups of requesters and may also be specified at a data class, data instance, template or request level. Definitions of privacy policies can also include policies on profile data held by third-parties. As such, it also handles requests for authorization for release of personal data held by a third-party, just as if the data was held directly by the current system. The Policy authorization engine also supports the data subject by providing the data requester with an explicit one time authorization for a particular request type as an alternative to privacy policy matching against data and requester class/group. The Authentication Engine 120 authenticates requesters of profile information, authorization or updates.
The Profile Responder 116 receives requests for profile information along with privacy statements on how the data will be used. It uses the Authentication engine 120 to authenticate the requester and uses the Policy authorization engine to check the authorization and privacy policies. It may need to check return from the Policy Authorization engine to see if external authorization is needed on any of the requested data, and handle requests to those external authorization sources. Similarly, it must recognize need for manual authorization and invoke the Manual Authorization Engine 111, if needed. It uses the Profile and Policy Managers to get only the subset of information that is allowed by the policy checks and uses the Logger component to record the request and the response. It also checks data returned by the query on the Policy Authorization engine 112 to see if some data needs to be obtained from an external source, and handles requests to those external sources. It also verifies and filters the response to ensure that no unauthorized data is returned. This step may not be necessary if queries for the exact allowed and requested data are used and supported. However, it may not be possible to trust external sources to return only the requested data since the query might return a larger set of data than the policies allow or was requested. Finally, it also supports requests for only authorization of release of data, and uses the Policy Authorization engine to return information on the data that is authorized for release under the requested policy.
The Manual Authorization Engine 111 provides the ability to perform manual authorization of a portion of the requested data. Invoked by the Profile Responder (or possibly the Policy Engine) to initiate a manual authorization, it sends an e-mail or otherwise notifies the data provider of the need for manual authorization. The data subject can use various computer programs 102, such as e-mail software, to respond to such a request.
The Profile Updater 113 receives requests to create, delete, or modify profile information. Like the Profile Responder, this component must authenticate the requester, log the request and response, check for authorization to make the profile update, and update the profile information.
The Interaction History Agent 114 provides support for user specification of what actions should be intercepted. This could be stored in the form of rules or explicit action types. An intermediary or proxy can then be used to intercept the desired online actions and record them as additional profile data.
The Profile Publisher 115 and the Privacy Policy Publisher 117 provide the user interfaces for specifying authorization information, privacy policies, profile data and templates. They can use the Profile and Policy Managers for reading and writing the information, or could go more indirectly through the Profile Updater and Profile Responder components.
The Manual Profile Responder 118 provides the user interfaces for gathering missing data in order to fulfill a profile data request. Invoked by the Profile Responder (or possibly the Profile Manager) to initiate entry of missing requested profile data. Sends an e-mail or otherwise notifies data provider for missing data entry. The e-mail can provide an easy way to launch a browser-based user interface to specify the needed data.
The Logger 119 supports logging of requests to and responses by the system, and uses the Profile Manager to make any updates to the profile.
In one embodiment, the Data Subject sets up data profiles and privacy policies using the Profile Publisher and the Privacy Policy Publisher. These would be stored in the Profile and Policy database, respectively. A Data Requester sends a request for data describing the data desired along with privacy policies describing the intended usage. The request is handled by the Profile Responder which uses the Authentication engine to verify the identity of the requester and the Policy Authorization engine to check the authority of the requester to access the requested data by using authorization rules and privacy policies, possibly invoking the Manual Authorization engine (to get manual authorizations). It then gathers the authorized data (possibly invoking the Manual Profile Responder to get missing data from the data subject), logs the request and reply using the Logger, updates the profile with this information using the Interaction History Agent, and send a reply along with the data to the data requester.
While the system described in FIG. 1 is capable of executing the processes described herein, this system is only one example of such a system. Those skilled in the art will appreciate that many other system designs are capable of performing the processes described herein.
FIG. 2 is a diagram of the data structure of an Authorization Rule 201. Each Authorization Rule 201 consists of four subelements: an Authorization Dataset 202, a Privacy Preference Rule 203, an Access List 204, and an Authorization Action 217. By expressing an Authorization Rule, a data subject defines a mapping from the first three subelements to a result action specified by the Authorization Action. In other words, an Authorization Rule declares that for a specified Authorization Dataset, the specified Privacy Preference Rule is applied for the specified Access List allow the specified Authorization Action.
The Authorization Dataset in a rule contains the data items that can be released according to the rule. Each authorization data set can be either a View Level 205 or a data type/object defined by a Class 209, a Property 210, an Instance 211, or a combination of these. A Class defines an object type (such as contact information), a Property defines a field within a Class (e.g. telephone number), and an Instance refers to a specific object (such as Joe's home-address). The combination of these may specify a data item constrained by all specified subelements. For example, specifying both class and property for a data item confines it to the property within the specified class. Moreover, a data subject can categorize his/her personal data into multiple View Levels (layers) so that the data in each View Level have the same privacy preference, access and authorization constraints, whereas data in different View Levels have different constraints. A View Level consists of a View Name 206, a Level Rank 208, and one or more Viewlevel Items 207. The View Name specifies which view this View Level belongs to, and the Level Rank declares which privacy level this View Level is confined with. The Level Rank can be used as a filter to retrieve the possible View Levels. Each Viewlevel item is further specified by a class, an instance, a property or a combination of them. Rules specified for a given View Level are inherited by View Levels of lower Level Ranks, unless overridden by rules specified by rules for the lower View Level, either for the entire level or for some class, instance, property or combination thereof of the dataset at the lower ranked View Level. By allowing the data subject to arrange all data into layers and associate privacy/access rules with each layer, the invention enables automated data exchange with considerable privacy protection for the data subject. All critical, highly personal data may be placed in one layer with very stringent privacy and access controls, while least sensitive data may be placed in a layer with the least amount of controls, with other data occupying intermediate layers. This, combined with the ability to associate rules with specific classes, instances, and properties of data gives the data subject a wide degree of flexibility in specifying different privacy and access controls for different categories of data, different types of requests, different classes of requesters, etc.
The Access List in a rule declares who can access the specified data set upon Privacy Preference matching. Each Access List contains one or more authorized Party 212, which can be a user 213, a group 214, a token 215, or “all” requesters 216. A user refers to a registered data requester, who has a userid and authentication data. A group contains multiple users, while one user may belong to multiple groups. A data subject can define one authorization rule for one or more groups of users who are then granted access to the data for the same privacy preference rules A token provides a way to allow controlled access to the data by limiting, for example, the number of times the data may be accessed. Any data requester in possession of the token is allowed access to the data as long as the token is valid. Moreover, a token may also be issued to a data requester to enable access to data that is held by a third party. The token is then presented by the data requester to the third-party which uses it to identify the requester as well as the data to which the requester is authorized. If the authorized party has the special value “all”, then access is granted to all requesters of the data for whom the privacy preference rules match. In such cases, and anyone can access the data as long as the privacy policies of the requester match those of the data subject.
The Authorization Action 217 declares which one of the actions should be taken if this rule is matched. The action “grant” 218 means that the request should be granted if this rule is matched, the action “notify” 219 specifies that data subject should be notified when the request is granted, and the action “get consent” 220 specifies that special consent should be obtained before the request can be granted.
The Privacy Preference Rule in an Authorization Rule specifies the privacy preference and action control that the data users in the access list have to satisfy in order to access the data.
FIG. 3 is an expansion of the Privacy Preference Rule 203 in FIG. 2. It explains the data structure for specifying a Privacy Preference Rule for the data requesters in the Access List to access the data in the Authorization Dataset. The Privacy Preference Rule 301 in an Authorization Rule contains two declarations: data subject's privacy preferences and access actions allowed by the data subject. The Privacy Preference 302 specifies why and how the data can be accessed in terms of the P3P standards. It includes several statements: Purpose 304, Retention 305, Recipient 306, and Access 307. The system may define other statements 308 based on a specific application domain requirements.
Purpose specifies the purposes for which the data can be acquired and processed. According to P3P, there are 13 sub-elements allowed in declaring Purpose. The privacy policy can contain one or more of the following:
    • <current/>: completion and support of current activity
    • <admin/>: Website and system administration
    • <develop/>: research and development
    • <customization/>: affirmative customization
    • <tailoring/>: one-time tailoring
    • <pseudo-analysis/>: pseudonymous analysis
    • <pseudo-decision/>: pseudonymous decision
    • <individual-analysis/>: individual analysis
    • <individual-decision/>: individual decision
    • <contact/>: contacting visitors for marketing of services or products
    • <historical/>: historical preservation
    • <telemarketing/>: telephone marketing
    • <other-purpose>string</other-purpose>
Since P3P was initially proposed for online personal information disclosure, one may need to add/delete/modify some sub-elements for the purpose of general privacy information control. Retention refers to the kind of retention policy applied to the data. According to P3P, there are 5 possible sub-elements in declaring Retention. The system may need to add/delete sub-elements for application purposes. A data subject can specify the retention using one of the following sub-elements.
    • <no-retention/>: information is not retained for more than a brief period of time
    • <stated-purpose/>: retained to meet the stated purpose
    • <legal-requirement/>: retained to meet a stated purpose but the destruction governed by legal requirements
    • <business-practices/>: retained in accordance with provider's business practices
    • <indefinitely/>: retained indefinitely
Recipient specifies the legal entity, or domain, beyond the requester where the data may be distributed. There are 6 possible sub-elements. The system may need to add/delete sub-elements for application purposes. A data subject can specify the retention using one of the following sub-elements.
    • <ours/>: ourselves and our entities/agents
    • <delivery/>: delivery services possibly following different practices
    • <same/>: legal services following our practices (policy)
    • <other-recipient/>: legal services following different practices
    • <unrelated/>: unrelated third party
    • <public/>: public fora
Access in the privacy preference describes whether the data in the corresponding authorization data set should be accessible by the data subject after the data has been released. Boolean values (true/false) are used to represent the access requirement flag. Different from the Purpose and Retention, Access declares the access capability that the requestor must provide to the data subject for his/her own data. Action control 303 specifies whether an access action is allowed. It contains several action permissions, each of which is represented by a boolean value. Action “create” 310 declares whether the data user can create the data, update 311 declares whether the data user can modify the data, and delete 312 declares whether the data user can delete the data. Additional actions 313 may be added according to application requirements.
FIG. 4 a is a block diagram of a Data Request Structure. A request for data is sent from a Data Requester to the Profile Responder, and shown in FIG. 1. A data request identifies a data subject, and includes a request for specific items of data from the data subject. The data request also specifies how it will use the data in the request, in the form of privacy declarations.
A data request consists of three parts: a Privacy Header 401, a Query 402, and Request Items 403. A Privacy Header consists of the name of the requester, the name of the responder, and a list of privacy declarations. Each privacy declaration has the structure of a Privacy Preference, as described in FIG. 3. The Query consists of sufficient information to uniquely identify the data subject from whom the data is desired. When the query is applied to the Profile Database (FIG. 1), it retrieves a data subject.
The list of Request Items identifies the specific data items being requested. Each request item consists of two parts: a reference 404 to one of the privacy declarations in the Privacy Header 401 and the name of one or more data items. The meaning of this pairing is the following: for each requested data item, if the request recipient (data subject) supplies this data item to the requester, then the requester promises to enforce the associated privacy declaration for that data item. Alternatively, if the same privacy declaration applies to more than one data items, then a request item can consist of a single privacy declaration reference 404 and multiple data item names.
FIG. 4 b is a block diagram of a Data Response Structure. A data response is sent from the Profile Responder of the system to the data requester, in response to a data request described in FIG. 4 a. A data response is either a denial, if the request cannot be fulfilled, or the subset of specific data items which were requested and authorized, along with associated privacy declarations representing the data subject's privacy preferences. A data response consists of two parts: a Privacy Header 410 and Response Items 411. A Privacy Header consists of the name of the responder, the name of the requester, and a list of privacy declarations. Each privacy declaration has the structure of a Privacy Preference, as described in FIG. 3. The list of Response Items is empty if the request cannot be fulfilled, either because the data subject profile does not exist, data requester is not authorized to access the data, or the privacy declarations in the request header do not match the privacy preferences associated with the subject profile. If the request can be fulfilled by the response system, then the list of response item is not empty. Each response item consists of two parts: a reference 412 to one of the privacy declarations in the Privacy Header and a data response. A data response is a name-value pair from the profile of the data subject, corresponding to a requested data item. Alternatively, if the same privacy declaration applies to more than one profile data items, then a response item can consist of a single privacy declaration reference and multiple response items.
FIG. 5 is a flow diagram of the Request Process, whereby the system receives a data request structure, processes it, and returns a data response structure to the requester. The Profile Responder receives the data request 501. The first step that the responder performs is to authenticate the requester 502. Authentication is the process of guaranteeing that the requester is who they say they are, and can be carried out in several ways, including the use of a userid and password, or a cookie, etc. If the authentication is not successful, then the response is returned with an empty response item list 505. If authentication succeeds, then the data request is passed to the Policy Authorization Engine which retrieves all Authorization Rules of the data subject specified in the request 503. The data subject is identified from the query in the request, which is applied to the profile database. Once the data subject is identified, all of the authorization rules are retrieved for him/her from the policy database. If there are no authorization rules for the data subject, the Profile Responder returns a response with an empty response item list. Otherwise, the next step is to examine the Access List of each of these retrieved authorization rules 504. For each access list, if the requester is not found in the access list, then the authorization rule is discarded. The requester is in the access list if the requester is either a user in the list or a user in a group which is in the list, or if the access list explicitly authorizes “all” requesters. After this process, if there are no authorization rules left, then the Profile Responder returns a response with an empty response item list. However, if any authorization rules still remain, the Policy Authorization Engine next compares the privacy declarations in the request with the Privacy Preference Rules in the authorization rules for each profile data item name in the request item 506. For each data item name in the query and in the request item list, the Policy Authorization Engine retrieves any privacy preferences from the authorization rules. It then performs the Policy-Preference matching process (see FIG. 6) for each data item. For each application of this matching process, the result is deny 507 or authorize 508, 509, or 510. If the result is deny, then the data item is not included in the list of data items to be returned in the response 511. If the result is authorized, then the data item is included in the response item list 512. Additionally, the authorization rule may require the data subject to be notified 513 or the consent of the data subject be obtained 514. After each data item name is processed, the next data item is retrieved for processing 515. When the entire request list has been processed, the data to be returned is gathered 516, the response structure is constructed and returned to the requester by the Profile Responder 517. If any of the data items have been denied, the Profile Responder may return an empty list to the requester, for more privacy security for the data subject.
FIG. 6 is a simple flow chart of the Data Requester Privacy Policy and Data Subject Privacy Preference Rule Matching process. The Privacy Preference Rule is specified by the Data Subject in the Authorization Rules as explained in FIG. 2 and FIG. 3, while the Data Requester's Privacy Policy is declared by the data requester as a part of the data request (FIG. 4 a). Since both the privacy preference rule and the privacy policy are based on the P3P standard, the matching process is to check the matching for each element.
Purpose checking 601 checks the purpose privacy statements. Both the privacy policy as well as the privacy preference rule purposes may contain one or more subelements. If the subelements declared in the privacy policy is a subset of the subelements specified in data subject's privacy preference rule, the purpose checking is successful and the matching algorithm proceeds to the retention statement check 602.
The Retention statement can be declared by one of the five subelements: <no-retention/>, <stated-purpose/>, <legal-requirement/>, <business-practices/> and <indefinitely/>. These subelements express different privacy levels, some of them are more restricted than others. The subelement <no-retention/> has the most restrictive privacy level, and the subelement (<indefinitely/>) is the least restricted. <stated-purpose/> is more restricted than <legal-requirement/> and <business-practices/>, both of which are more restricted than <indefinitely/>. There is no order between <legal-requirement/> and <business-practices>. The retention statement check proceeds according to this particular order.
Recipient checking 603 then checks the matching for recipient statement. The recipient statement can be declared by one of the six subelements: <ours/>, <delivery>, <same/>, <other-recipient/>, <unrelated/>, and <public/>. These subelements express different privacy levels with <ours/> being the most restrictive, followed by <same/> and <delivery/>, then <other-recipient/> and <unrelated/>, with <public> being the least restrictive. The matching process is successful if the recipient declared in the privacy policy is not less restricted than the recipient specified in the privacy preference rule.
Access checking 604 checks the matching for the requirements of the capability for a data subject to access the data after a data requester acquires the data. The access checking is successful if the access requirement of the data subject is satisfied by the access statement declared in the policy. Finally, Action control checking 605 checks if the actions requested by the data requester are allowed according to the action control specified in data subject's privacy preference rule. If no action control is specified, read is assumed and allowed. This is done by simple checking the corresponding Boolean tag of a specific action in the preference. If all the checking is successful, the request is authorized 606, otherwise any failure along the matching process causes the request to be denied 607.
FIG. 7 is a flow diagram of a routine that enables a gather and filtering process carried out to collect data to be returned to a data requester. As described in FIG. 6, the process of matching the privacy policy of the data requester with the authorization rules specified for the requested data by the data subject results in a list of such data items that are to be returned to the data requester. This flow diagram described the various steps that could be potentially involved in the gathering of such data. In step 700, the system examines the list of data items to be returned. If all the data is available locally on the system 701, the system collects it 702, prepares the reply structure 710 and sends it to the data requester 711. If, however, all data is not available locally, then the system collects whatever data is locally available 703. It then checks if some of the data items have missing values 704. If yes, it contacts the data subject and retrieves the required data items from him/her 705. In step 706, the system determines if the data that is not available locally is available from third parties. If it is available, then the system retrieves the data from the third parties holding the data in step 707. It then filters the data again in step 708 by matching the data returned by the third parties with the request of the data requester and the privacy policies and authorization rules of the data subject. This ensures that only that data is returned that is allowed. In step 709, the system authorizes the release of any data that is held by third parties but is not available for release by the system itself (must be directly requested from the third parties by the data requester). The system then prepares a reply for the data requester 710 by collecting together all the data (locally collected or retrieved from third parties) as well as information about the data authorized to be released by third parties. It then sends this reply to the data requester 711. Thus, by enabling the gather and filter process, a data requester can get data held not only by the system locally but also held by third parties, either via collection by the system itself or directly from third parties after authorization by the system. Since the data subject provides authorization rules describing the privacy preferences and access permissions for all data that is held locally or by third parties, the process ensures that only that data is released, or authorized to be released, for which the data requester is authorized and for which the requesters privacy policies match that of the data subject.
FIG. 8 describes one method of doing business with the current invention wherein the subject data is distributed across multiple enterprises, and a trusted third party is used as a data subject's personal data service to handle and process requests for data owned by the data subject as well as by the various enterprises (third party data suppliers). In this method of doing business, a trusted third party acts as a Personal Data Service (PDS) 804 for the Data Subject 800, and provides a server-based, possibly distributed, environment for hosting the data that is owned by the data subject himself. The data subject may choose to store all such data in the PDS profile repository 806, or store some of it on his own personal machine profile repository 802. Similarly, the data subject may store his privacy policies entirely on the PDS policy repository 807, or distribute them between the PDS repository and his personal system policy repository 803. These policies may cover both data that is owned by the data subject and resides either on the PDS or on the data subject's personal system, as well as data that is owned by, and resides with, third party Data Suppliers 814 in their profile repositories 818. Additionally the PDS hosts all components 805 (described in FIG. 1) for creating and managing profiles, publishing privacy and authorization preferences, handling and responding to requests, authenticating requesters and privacy policy matching as well as releasing or authorizing release of data. Similarly, the data subject's personal system also hosts several software components 801, including local copies of the profile and policy publishers and managers to help publish and manage the data and policies that reside on the data subject's personal system, as well as e-mail and web browser software to help publish profiles and policies on the PDS, provide manual authorization and missing data responses 812 as well as handle notifications 811 from the PDS. A Data Requester 808 must also have a minimal set of software components 809 such as a local policy publisher and manager for the data requester's privacy policies stored in its policy repository 810. Finally, each Data Supplier 814 which owns and stores part of the data subject's data must also host some of the software components 817 for managing the data subject's data they store in their profile repository 818 as well as for handling data requests from, and sending responses to, the PDS. In this method of doing business, the PDS acts as an agent of the Data Subject. A Data Subject would register with the PDS and store his Profile as well as Privacy Policies with the PDS. The Data Subject may choose to keep part of the Profile and Privacy policies on his own personal system as well. The profile and privacy policies stored with the PDS will include information on where missing information is available, either from the Data Subject's personal system or from third-party Data Suppliers. Similarly, Data Requesters would also be required to register with the PDS. A Data Requester desiring access to some data about a Data subject then sends a request 813 to the PDS identifying the Data Subject as well as the data requested, along with its own privacy policies on how the requested data would be used. Using the various software components 805, as described earlier in FIG. 1 and elsewhere, the PDS then authenticates the requester and matches the privacy policies of the requester with the authorization rules/privacy preference rules specified by the Data Subject. If manual authorization is needed for some data, the PDS requests such authorization 811 from the Data subject. Once the policy matching and authorization process is completed, the PDS carries out a gather and filtering process, as described in FIG. 7, to collect the data to be returned to the Data Requester. The PDS collects all data that is locally available, and sends a request to the Data Subject to get any data that is available only from the personal system of the Data Subject. If any requested data is available from third-party Data suppliers, 814, the PDS sends requests 815 for such data to the Data Suppliers. The profile responder 817 run by a data supplier handles such requests from the PDS, and sends the data back to the PDS. Alternatively, the PDS just sends the Data Supplier an authorization to release the data directly to the Data Requester when so requested. Once all the data has been collected, or authorized to be released, the PDS sends it to the Data Requester along with information about any third party data suppliers to contact for remaining data. The Data Requester may then get this data directly from the Data Suppliers.
This method of doing business has several features of benefit to all the parties involved. The PDS acts as a trusted agent for the Data Subject, and relieves the subject of the responsibility of hosting the data and policies as well as handling and processing requests of data from Data Requesters. Moreover, it can function as a fully automatic system, requiring no intervention by the data subject once the profile and privacy policies have been set, in most circumstances. From a Data Requester's point of view, this method is beneficial as well since it has to send one request for data to the PDS to get data that is owned by the Data Subject as well as by other Data Suppliers. Finally, this method provides an independent service provider the ability to act as a PDS, and provide the server platform and hosting service as a fee-based service for Data Requesters and Data Subjects.
FIG. 9 describes a method of doing business with the current invention wherein subject data is distributed across multiple enterprises, with each enterprise holding enterprise-specific data and privacy preferences of the data subject, and accepting and processing requests for data held by it directly from interested data requesters. In this method of doing business, every enterprise that holds any data belonging to the Data Subject 900 runs all privacy-software components 905 (described in FIG. 1) for creating and managing privacy and authorization preferences, handling and responding to requests, authenticating requesters, performing privacy policy matching as well as releasing data. These include all third-party Data Suppliers 910 as well as Data Requesters 908, the two being interchangeable in that any enterprise can be a requester of data, or a supplier of data, at different times. Additionally, each such enterprise has several other components 909, including a repository of its own privacy policies describing how it uses any requested data along with a local policy publisher and manager for managing such policies, as well as a repository of Data Subject's privacy policies governing the release of the Data Subject's data that is owned and held by the enterprise. Each enterprise is thus responsible for storing a Data subject's privacy policies as well as handling and processing any requests made for such data by any Data Requesters. A Data Subject publishes 911 his privacy preference policies directly with each potential enterprise that holds any data on the Data Subject. A Data Requester 908 too directly sends its data request 913, along with its privacy policy, to the Data Supplier which holds the requested data. The Data Supplier 910 then uses the various privacy-software components 905, as described in FIG. 1, to authenticate the requester and match the privacy policies of the Data Requester with those specified by the Data Subject (and stored in the Supplier's policy repository) to decide whether to release the data. If manual authorization or some missing values are needed for some data, the Data Supplier requests such authorization 912 from the Data Subject. To enable the Data Subject to publish his privacy policies as well as respond to such requests from the Data Suppliers, his personal system also hosts several software components 901, such e-mail and web browser. Finally, the Data Subject may still choose to use a trusted third-party as his Personal Data Service (PDS) 904 to manage access to personal data that is owned by the Data Subject. As in the case of the enterprises that hold any of the Data Subject's data, the PDS runs all the privacy-software components 905 to help it receive and process requests for the data owned by the Data subject, as well as a repository of such data 906 and privacy-preferences governing access to such data 907. Also, the Data Subject may choose to keep some of the data, as well as policies, on repositories 902 and 903 on his personal system, along with privacy-software components to manage them 901. A Data Requester who needs data that is owned and held by the Data subject would then send such a request 913 to the PDS, which would process the request and respond with the data, with optional contact 911/912 with the Data Subject's system. This method of doing business has several features of benefit to all the parties involved. Since every enterprise runs the various privacy-software components, and stores the Data Subject's privacy preferences governing the data owned/stored by the enterprise, it is easy for enterprises to maintain and share data amongst them, according to the privacy preferences of the Data Subject. Moreover, it also enables enterprises to show the Data Subject's the data they have about him. Finally, the Data Subject can still choose to use a PDS to act as his trusted agent for hosting the data that he owns as well as handling and processing requests for that data from Data Requesters.
While the invention has been shown and described with reference to particular embodiments thereof, it will be understood by those skilled in the art that the foregoing and other changes in form and detail may be made herein without departing from the spirit and scope of the invention. The appended claims are to encompass within their scope all such changes and modifications as are within the true spirit and scope of this invention.

Claims (19)

1. A method to enforce privacy preferences on exchanges of personal data of a data-subject, comprising the steps of:
specifying one or more data-subject authorization rule sets, the data-subject authorization rule set having one or more subject constraints on one or more data-subject data;
receiving a request message from a requester, the request message having one or more requests for one or more of the data-subject data pertaining to the a subject, and a requester privacy statement for each of the respective data-subject data requested, wherein the requester privacy statement includes purpose, retention, recipient, and access information, wherein the purpose information specifies the purpose for which the requested data is acquired, the retention information specifies a retention policy for the requested data, the recipient information specifies the recipients of the requested data, and the access information specifies whether the requested data should be accessible to the data-subject after the data has been released;
comparing the requester privacy statement to the subject constraints; and
releasing the data-subject data in a response message to the requester only if the subject constraints are satisfied.
2. The method of claim 1, further comprising the step of authorizing the requester to receive the data-subject data.
3. The method of claim 2, wherein the step of authorizing the requester includes the steps of authorization at more than one level.
4. The method of claim 1, wherein the step of specifying one or more data-subject authorization rule sets, the data-subject authorization rule set having one or more subject constraints includes the steps of:
specifying an authorization dataset describing the data to which the constraint applies; specifying a privacy preference rule that describes the privacy preferences under which the data-subject data may be released and the corresponding actions allowed;
specifying an access list describing who is allowed to access the said data; and
specifying an authorization action that describes any additional action to be taken if the restrictions imposed by the authorization dataset, the privacy preference rule and the access list of this constraint are matched.
5. The method of claim 1, wherein the step of specifying one or more data-subject authorization rule sets, the data-subject authorization rule set having one or more subject constraints includes the steps of:
specifying such constraints for subject data that owned and held by the subject;
specifying such constraints for data-subject data that is owned by the data subject, but held by one or more parties on behalf of the subject; and
specifying such constraints for data-subject data that is owned and held by one or more third parties.
6. The method of claim 1, wherein the step of specifying one or more data-subject authorization rule sets includes the steps of specifying different data-subject authorization rule sets for the same data-subject data for one or more requesters that must be satisfied for the data-subject data to be released.
7. The method of claim 1, wherein the step of comparing the requester privacy statement to the subject constraints includes the step of partitioning the data-subject data into a first part that satisfies the constraints and is released and a second part that does not satisfy the constraints and is not released.
8. The method of claim 1, wherein the step of releasing the data-subject data includes the step of getting manual authorization from the data-subject for some of the data-subject data before releasing the data.
9. The method of claim 1, wherein the step of releasing the data-subject data includes the step of getting one or more missing values from the data-subject before releasing the data.
10. The method of claim 1, wherein the step of releasing the data-subject data includes the step of getting one or more data-subject data from one or more third parties, that store that data-subject data, before releasing the data.
11. The method of claim 1, wherein the step of releasing the data includes the step of providing authorization to one or more third parties holding part of the data-subject data to release the part to the requester.
12. The method of claim 1, wherein the step of specifying one or more data-subject authorization rule sets, the data-subject authorization rule set having one or more subject constraints includes the steps of:
ordering the data-subject data in a hierarchy with one or more levels; and
specifying one or more constraints for each level that apply to the data-subject data in that level.
13. The method of claim 1, wherein the step of specifying each subject constraint includes the step of specifying one or more of the following: one or more classes of data, one or more properties of data, and one or more instances of data.
14. The method of claim 12, wherein the step of specifying constraints for each level includes the step of specifying different constraints for one or more of the levels.
15. The method of claim 12, wherein the step of specifying constraints for each level includes the step of inheriting the constraints from one or more other levels.
16. The method of claim 12, wherein the step of ordering the data-subject data into a hierarchy of levels includes the step of creating levels from one or more classes of data, properties of data, instances of data, or a combination thereof these.
17. The method of claim 1, wherein the step of specifying one or more data-subject authorization rule sets, the data-subject authorization rule set having one or more subject constraints includes the steps of specifying constraints that include privacy preferences based on any one or more of a Platform for Privacy Preferences (P3P) standard privacy statements.
18. A method, as in claim 17 where the standard privacy statements include any one or more of the following: a purpose, a retention, a recipient and an access.
19. The method of claim 1, wherein the step of specifying one or more data-subject authorization rule sets, the data-subject authorization rule set having one or more subject constraints includes the steps of specifying constraints over subject data that includes any one or more of the following: a privacy data, a privacy data associated a natural person, a confidential information, and a trade secret.
US10/046,034 2001-11-07 2001-11-07 System, method, and business methods for enforcing privacy preferences on personal-data exchanges across a network Active 2026-03-26 US7478157B2 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US10/046,034 US7478157B2 (en) 2001-11-07 2001-11-07 System, method, and business methods for enforcing privacy preferences on personal-data exchanges across a network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
US10/046,034 US7478157B2 (en) 2001-11-07 2001-11-07 System, method, and business methods for enforcing privacy preferences on personal-data exchanges across a network

Publications (2)

Publication Number Publication Date
US20030088520A1 US20030088520A1 (en) 2003-05-08
US7478157B2 true US7478157B2 (en) 2009-01-13

Family

ID=21941216

Family Applications (1)

Application Number Title Priority Date Filing Date
US10/046,034 Active 2026-03-26 US7478157B2 (en) 2001-11-07 2001-11-07 System, method, and business methods for enforcing privacy preferences on personal-data exchanges across a network

Country Status (1)

Country Link
US (1) US7478157B2 (en)

Cited By (245)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030004734A1 (en) * 2001-06-19 2003-01-02 International Business Machines Corporation Using an object model to improve handling of personally identifiable information
US20050132188A1 (en) * 2003-05-20 2005-06-16 Khin Peter M. Methods and systems for determining security requirements for an information resource
US20060111874A1 (en) * 2004-09-30 2006-05-25 Blazant, Inx. Method and system for filtering, organizing and presenting selected information technology information as a function of business dimensions
US20070282982A1 (en) * 2006-06-05 2007-12-06 Rhonda Childress Policy-Based Management in a Computer Environment
US20080028435A1 (en) * 2003-05-20 2008-01-31 Strickland Zoe C C Methods and systems for determining privacy requirements for an informatin resource
US20080256643A1 (en) * 2007-04-13 2008-10-16 Microsoft Corporation Multiple entity authorization model
US20080313154A1 (en) * 2007-06-12 2008-12-18 At&T Delaware Intellectual Property, Inc. Method and apparatus for managing contact information
US20090100136A1 (en) * 2007-10-15 2009-04-16 Sony Ericsson Mobile Communications Ab Intelligent presence
US20090106815A1 (en) * 2007-10-23 2009-04-23 International Business Machines Corporation Method for mapping privacy policies to classification labels
US20090300512A1 (en) * 2008-05-27 2009-12-03 Open Invention Network Llc Preference editor to facilitate privacy controls over user identities
US20090300509A1 (en) * 2004-02-23 2009-12-03 Microsoft Corporation Profile and consent accrual
US20100145840A1 (en) * 2003-03-21 2010-06-10 Mighty Net, Inc. Card management system and method
US20110060905A1 (en) * 2009-05-11 2011-03-10 Experian Marketing Solutions, Inc. Systems and methods for providing anonymized user profile data
US20110119732A1 (en) * 2002-02-27 2011-05-19 Microsoft Corporation System and method for user-centric authorization to access user-specific information
US20110219423A1 (en) * 2010-03-05 2011-09-08 Nokia Corporation Method and apparatus for triggering user communications based on privacy information
US20110252226A1 (en) * 2010-04-10 2011-10-13 Max Planck Gesellschaft Zur Foerderung Der Wissenschaften Preserving user privacy in response to user interactions
US8175889B1 (en) 2005-04-06 2012-05-08 Experian Information Solutions, Inc. Systems and methods for tracking changes of address based on service disconnect/connect data
US20120167234A1 (en) * 2010-12-28 2012-06-28 Verizon Patent And Licensing, Inc. Persona-based identity management system
US8478674B1 (en) 2010-11-12 2013-07-02 Consumerinfo.Com, Inc. Application clusters
US20130174211A1 (en) * 2011-12-30 2013-07-04 Nokia Corporation Method And Apparatus Providing Privacy Setting And Monitoring User Interface
US20130332578A1 (en) * 2012-06-08 2013-12-12 MyClassicGarage, LLC Method and System for Storage and Selective Sharing of Vehicle Data
US8744956B1 (en) 2010-07-01 2014-06-03 Experian Information Solutions, Inc. Systems and methods for permission arbitrated transaction services
US8856894B1 (en) 2012-11-28 2014-10-07 Consumerinfo.Com, Inc. Always on authentication
US8893297B2 (en) 2012-11-21 2014-11-18 Solomo Identity, Llc Personal data management system with sharing revocation
US8931058B2 (en) 2010-07-01 2015-01-06 Experian Information Solutions, Inc. Systems and methods for permission arbitrated transaction services
US9081986B2 (en) 2012-05-07 2015-07-14 Nokia Technologies Oy Method and apparatus for user information exchange
US9092796B2 (en) 2012-11-21 2015-07-28 Solomo Identity, Llc. Personal data management system with global data store
US9147042B1 (en) 2010-11-22 2015-09-29 Experian Information Solutions, Inc. Systems and methods for data verification
US20160034712A1 (en) * 2012-10-02 2016-02-04 Banjo, Inc. System and method for event-related content discovery, curation, and presentation
US9256904B1 (en) 2008-08-14 2016-02-09 Experian Information Solutions, Inc. Multi-bureau credit file freeze and unfreeze
US9277364B2 (en) 2012-06-25 2016-03-01 Nokia Technologies Oy Methods and apparatus for reporting location privacy
US9342783B1 (en) 2007-03-30 2016-05-17 Consumerinfo.Com, Inc. Systems and methods for data verification
US9529851B1 (en) 2013-12-02 2016-12-27 Experian Information Solutions, Inc. Server architecture for electronic data quality processing
US9542553B1 (en) 2011-09-16 2017-01-10 Consumerinfo.Com, Inc. Systems and methods of identity protection and management
US9558519B1 (en) 2011-04-29 2017-01-31 Consumerinfo.Com, Inc. Exposing reporting cycle information
US9607336B1 (en) 2011-06-16 2017-03-28 Consumerinfo.Com, Inc. Providing credit inquiry alerts
US9633322B1 (en) 2013-03-15 2017-04-25 Consumerinfo.Com, Inc. Adjustment of knowledge-based authentication
US9652525B2 (en) 2012-10-02 2017-05-16 Banjo, Inc. Dynamic event detection system and method
US9691090B1 (en) * 2016-04-01 2017-06-27 OneTrust, LLC Data processing systems and methods for operationalizing privacy compliance and assessing the risk of various respective privacy campaigns
US9697263B1 (en) 2013-03-04 2017-07-04 Experian Information Solutions, Inc. Consumer data request fulfillment system
US9721147B1 (en) 2013-05-23 2017-08-01 Consumerinfo.Com, Inc. Digital identity
US9729583B1 (en) 2016-06-10 2017-08-08 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US9817997B2 (en) 2014-12-18 2017-11-14 Banjo, Inc. User-generated content permissions status analysis system and method
US9851966B1 (en) 2016-06-10 2017-12-26 OneTrust, LLC Data processing systems and communications systems and methods for integrating privacy compliance systems with software development and agile tools for privacy design
US9858439B1 (en) 2017-06-16 2018-01-02 OneTrust, LLC Data processing systems for identifying whether cookies contain personally identifying information
US9892443B2 (en) 2016-04-01 2018-02-13 OneTrust, LLC Data processing systems for modifying privacy campaign data via electronic messaging systems
US9892442B2 (en) 2016-04-01 2018-02-13 OneTrust, LLC Data processing systems and methods for efficiently assessing the risk of privacy campaigns
US9892444B2 (en) 2016-04-01 2018-02-13 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US9898769B2 (en) 2016-04-01 2018-02-20 OneTrust, LLC Data processing systems and methods for operationalizing privacy compliance via integrated mobile applications
US9934368B2 (en) 2012-10-02 2018-04-03 Banjo, Inc. User-generated content permissions status analysis system and method
US10013577B1 (en) 2017-06-16 2018-07-03 OneTrust, LLC Data processing systems for identifying whether cookies contain personally identifying information
US10019597B2 (en) 2016-06-10 2018-07-10 OneTrust, LLC Data processing systems and communications systems and methods for integrating privacy compliance systems with software development and agile tools for privacy design
US10026110B2 (en) 2016-04-01 2018-07-17 OneTrust, LLC Data processing systems and methods for generating personal data inventories for organizations and other entities
US10032172B2 (en) 2016-06-10 2018-07-24 OneTrust, LLC Data processing systems for measuring privacy maturity within an organization
US10075446B2 (en) 2008-06-26 2018-09-11 Experian Marketing Solutions, Inc. Systems and methods for providing an integrated identifier
WO2018170504A1 (en) * 2017-03-17 2018-09-20 Labyrinth Research Llc Unified control of privacy-impacting devices
US10102536B1 (en) 2013-11-15 2018-10-16 Experian Information Solutions, Inc. Micro-geographic aggregation system
US10102533B2 (en) 2016-06-10 2018-10-16 OneTrust, LLC Data processing and communications systems and methods for the efficient implementation of privacy by design
US10104103B1 (en) 2018-01-19 2018-10-16 OneTrust, LLC Data processing systems for tracking reputational risk via scanning and registry lookup
US10121015B2 (en) * 2014-02-21 2018-11-06 Lens Ventures, Llc Management of data privacy and security in a pervasive computing environment
US10169609B1 (en) 2016-06-10 2019-01-01 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10176503B2 (en) 2016-04-01 2019-01-08 OneTrust, LLC Data processing systems and methods for efficiently assessing the risk of privacy campaigns
US10176502B2 (en) 2016-04-01 2019-01-08 OneTrust, LLC Data processing systems and methods for integrating privacy information management systems with data loss prevention tools or other tools for privacy design
US10181019B2 (en) 2016-06-10 2019-01-15 OneTrust, LLC Data processing systems and communications systems and methods for integrating privacy compliance systems with software development and agile tools for privacy design
US10181051B2 (en) 2016-06-10 2019-01-15 OneTrust, LLC Data processing systems for generating and populating a data inventory for processing data access requests
US10204154B2 (en) 2016-06-10 2019-02-12 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10235534B2 (en) 2016-06-10 2019-03-19 OneTrust, LLC Data processing systems for prioritizing data subject access requests for fulfillment and related methods
US10242228B2 (en) 2016-06-10 2019-03-26 OneTrust, LLC Data processing systems for measuring privacy maturity within an organization
US10255598B1 (en) 2012-12-06 2019-04-09 Consumerinfo.Com, Inc. Credit card account data extraction
US10262362B1 (en) 2014-02-14 2019-04-16 Experian Information Solutions, Inc. Automatic generation of code for attributes
US10275614B2 (en) 2016-06-10 2019-04-30 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10284604B2 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing and scanning systems for generating and populating a data inventory
US10282700B2 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10282559B2 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US10282692B2 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US10289866B2 (en) 2016-06-10 2019-05-14 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10289870B2 (en) 2016-06-10 2019-05-14 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10289867B2 (en) 2014-07-27 2019-05-14 OneTrust, LLC Data processing systems for webform crawling to map processing activities and related methods
US10318761B2 (en) 2016-06-10 2019-06-11 OneTrust, LLC Data processing systems and methods for auditing data request compliance
US10346638B2 (en) 2016-06-10 2019-07-09 OneTrust, LLC Data processing systems for identifying and modifying processes that are subject to data subject access requests
US10346637B2 (en) 2016-06-10 2019-07-09 OneTrust, LLC Data processing systems for the identification and deletion of personal data in computer systems
US10353674B2 (en) 2016-06-10 2019-07-16 OneTrust, LLC Data processing and communications systems and methods for the efficient implementation of privacy by design
US10353673B2 (en) 2016-06-10 2019-07-16 OneTrust, LLC Data processing systems for integration of consumer feedback with data subject access requests and related methods
US10360352B2 (en) 2012-10-02 2019-07-23 Banjo, Inc. System and method for event-based vehicle operation
US10373240B1 (en) 2014-04-25 2019-08-06 Csidentity Corporation Systems, methods and computer-program products for eligibility verification
US20190273820A1 (en) * 2017-11-20 2019-09-05 International Business Machines Corporation Non-verbal sensitive data authentication
US10417704B2 (en) 2010-11-02 2019-09-17 Experian Technology Ltd. Systems and methods of assisted strategy design
US10416966B2 (en) 2016-06-10 2019-09-17 OneTrust, LLC Data processing systems for identity validation of data subject access requests and related methods
US10423996B2 (en) 2016-04-01 2019-09-24 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US10430740B2 (en) 2016-06-10 2019-10-01 One Trust, LLC Data processing systems for calculating and communicating cost of fulfilling data subject access requests and related methods
US10438017B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Data processing systems for processing data subject access requests
US10440062B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Consent receipt management systems and related methods
US10437412B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Consent receipt management systems and related methods
US10452866B2 (en) 2016-06-10 2019-10-22 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10452864B2 (en) 2016-06-10 2019-10-22 OneTrust, LLC Data processing systems for webform crawling to map processing activities and related methods
US10454973B2 (en) 2016-06-10 2019-10-22 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10467432B2 (en) 2016-06-10 2019-11-05 OneTrust, LLC Data processing systems for use in automatically generating, populating, and submitting data subject access requests
US10496803B2 (en) 2016-06-10 2019-12-03 OneTrust, LLC Data processing systems and methods for efficiently assessing the risk of privacy campaigns
US10496846B1 (en) 2016-06-10 2019-12-03 OneTrust, LLC Data processing and communications systems and methods for the efficient implementation of privacy by design
US10503926B2 (en) 2016-06-10 2019-12-10 OneTrust, LLC Consent receipt management systems and related methods
US10510031B2 (en) 2016-06-10 2019-12-17 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US10509894B2 (en) 2016-06-10 2019-12-17 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US10509920B2 (en) 2016-06-10 2019-12-17 OneTrust, LLC Data processing systems for processing data subject access requests
US10565161B2 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for processing data subject access requests
US10565236B1 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10565397B1 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10572686B2 (en) 2016-06-10 2020-02-25 OneTrust, LLC Consent receipt management systems and related methods
US10586075B2 (en) 2016-06-10 2020-03-10 OneTrust, LLC Data processing systems for orphaned data identification and deletion and related methods
US10585968B2 (en) 2016-06-10 2020-03-10 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10592648B2 (en) 2016-06-10 2020-03-17 OneTrust, LLC Consent receipt management systems and related methods
US10592692B2 (en) 2016-06-10 2020-03-17 OneTrust, LLC Data processing systems for central consent repository and related methods
US10606916B2 (en) 2016-06-10 2020-03-31 OneTrust, LLC Data processing user interface monitoring systems and related methods
US10607028B2 (en) 2016-06-10 2020-03-31 OneTrust, LLC Data processing systems for data testing to confirm data deletion and related methods
US10614247B2 (en) 2016-06-10 2020-04-07 OneTrust, LLC Data processing systems for automated classification of personal information from documents and related methods
US20200126133A1 (en) * 2016-04-01 2020-04-23 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US10642870B2 (en) 2016-06-10 2020-05-05 OneTrust, LLC Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software
US10664936B2 (en) 2013-03-15 2020-05-26 Csidentity Corporation Authentication systems and methods for on-demand products
US10678945B2 (en) 2016-06-10 2020-06-09 OneTrust, LLC Consent receipt management systems and related methods
US10678815B2 (en) 2012-10-02 2020-06-09 Banjo, Inc. Dynamic event detection system and method
US10685140B2 (en) 2016-06-10 2020-06-16 OneTrust, LLC Consent receipt management systems and related methods
US10706176B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data-processing consent refresh, re-prompt, and recapture systems and related methods
US10706379B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data processing systems for automatic preparation for remediation and related methods
US10708305B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Automated data processing systems and methods for automatically processing requests for privacy-related information
US10706174B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data processing systems for prioritizing data subject access requests for fulfillment and related methods
US10706131B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data processing systems and methods for efficiently assessing the risk of privacy campaigns
US10713387B2 (en) 2016-06-10 2020-07-14 OneTrust, LLC Consent conversion optimization systems and related methods
US10726158B2 (en) 2016-06-10 2020-07-28 OneTrust, LLC Consent receipt management and automated process blocking systems and related methods
US10735183B1 (en) 2017-06-30 2020-08-04 Experian Information Solutions, Inc. Symmetric encryption for private smart contracts among multiple parties in a private peer-to-peer network
US10740487B2 (en) 2016-06-10 2020-08-11 OneTrust, LLC Data processing systems and methods for populating and maintaining a centralized database of personal data
US10757154B1 (en) 2015-11-24 2020-08-25 Experian Information Solutions, Inc. Real-time event-based notification system
US10762236B2 (en) 2016-06-10 2020-09-01 OneTrust, LLC Data processing user interface monitoring systems and related methods
US10769301B2 (en) 2016-06-10 2020-09-08 OneTrust, LLC Data processing systems for webform crawling to map processing activities and related methods
US10776518B2 (en) 2016-06-10 2020-09-15 OneTrust, LLC Consent receipt management systems and related methods
US10776517B2 (en) 2016-06-10 2020-09-15 OneTrust, LLC Data processing systems for calculating and communicating cost of fulfilling data subject access requests and related methods
US10776514B2 (en) 2016-06-10 2020-09-15 OneTrust, LLC Data processing systems for the identification and deletion of personal data in computer systems
US10783256B2 (en) 2016-06-10 2020-09-22 OneTrust, LLC Data processing systems for data transfer risk identification and related methods
US10798133B2 (en) 2016-06-10 2020-10-06 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10796260B2 (en) 2016-06-10 2020-10-06 OneTrust, LLC Privacy management systems and methods
US10803200B2 (en) 2016-06-10 2020-10-13 OneTrust, LLC Data processing systems for processing and managing data subject access in a distributed environment
US10803202B2 (en) 2018-09-07 2020-10-13 OneTrust, LLC Data processing systems for orphaned data identification and deletion and related methods
US10839102B2 (en) 2016-06-10 2020-11-17 OneTrust, LLC Data processing systems for identifying and modifying processes that are subject to data subject access requests
US10848523B2 (en) 2016-06-10 2020-11-24 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10846433B2 (en) 2016-06-10 2020-11-24 OneTrust, LLC Data processing consent management systems and related methods
US10853501B2 (en) 2016-06-10 2020-12-01 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US10873606B2 (en) 2016-06-10 2020-12-22 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10878127B2 (en) 2016-06-10 2020-12-29 OneTrust, LLC Data subject access request processing systems and related methods
US10885485B2 (en) 2016-06-10 2021-01-05 OneTrust, LLC Privacy management systems and methods
US10896394B2 (en) 2016-06-10 2021-01-19 OneTrust, LLC Privacy management systems and methods
WO2021015957A1 (en) 2019-07-23 2021-01-28 Allstate Insurance Company Safe logon
US10909488B2 (en) 2016-06-10 2021-02-02 OneTrust, LLC Data processing systems for assessing readiness for responding to privacy-related incidents
US10909617B2 (en) 2010-03-24 2021-02-02 Consumerinfo.Com, Inc. Indirect monitoring and reporting of a user's credit data
US10911234B2 (en) 2018-06-22 2021-02-02 Experian Information Solutions, Inc. System and method for a token gateway environment
US10909265B2 (en) 2016-06-10 2021-02-02 OneTrust, LLC Application privacy scanning systems and related methods
US10944725B2 (en) 2016-06-10 2021-03-09 OneTrust, LLC Data processing systems and methods for using a data model to select a target data asset in a data migration
US10949565B2 (en) 2016-06-10 2021-03-16 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10949170B2 (en) 2016-06-10 2021-03-16 OneTrust, LLC Data processing systems for integration of consumer feedback with data subject access requests and related methods
US10963434B1 (en) 2018-09-07 2021-03-30 Experian Information Solutions, Inc. Data architecture for supporting multiple search models
US10997318B2 (en) 2016-06-10 2021-05-04 OneTrust, LLC Data processing systems for generating and populating a data inventory for processing data access requests
US10997315B2 (en) 2016-06-10 2021-05-04 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11004125B2 (en) * 2016-04-01 2021-05-11 OneTrust, LLC Data processing systems and methods for integrating privacy information management systems with data loss prevention tools or other tools for privacy design
US11025675B2 (en) 2016-06-10 2021-06-01 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US11023842B2 (en) 2016-06-10 2021-06-01 OneTrust, LLC Data processing systems and methods for bundled privacy policies
US11030562B1 (en) 2011-10-31 2021-06-08 Consumerinfo.Com, Inc. Pre-data breach monitoring
US11038925B2 (en) 2016-06-10 2021-06-15 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11057356B2 (en) 2016-06-10 2021-07-06 OneTrust, LLC Automated data processing systems and methods for automatically processing data subject access requests using a chatbot
US11074367B2 (en) 2016-06-10 2021-07-27 OneTrust, LLC Data processing systems for identity validation for consumer rights requests and related methods
US11087260B2 (en) 2016-06-10 2021-08-10 OneTrust, LLC Data processing systems and methods for customizing privacy training
US11100444B2 (en) 2016-06-10 2021-08-24 OneTrust, LLC Data processing systems and methods for providing training in a vendor procurement process
US11134086B2 (en) 2016-06-10 2021-09-28 OneTrust, LLC Consent conversion optimization systems and related methods
US11138299B2 (en) 2016-06-10 2021-10-05 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11138242B2 (en) 2016-06-10 2021-10-05 OneTrust, LLC Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software
US11144622B2 (en) 2016-06-10 2021-10-12 OneTrust, LLC Privacy management systems and methods
US11144675B2 (en) 2018-09-07 2021-10-12 OneTrust, LLC Data processing systems and methods for automatically protecting sensitive data within privacy management systems
US11146566B2 (en) 2016-06-10 2021-10-12 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11151233B2 (en) 2016-06-10 2021-10-19 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11157600B2 (en) 2016-06-10 2021-10-26 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11188862B2 (en) 2016-06-10 2021-11-30 OneTrust, LLC Privacy management systems and methods
US11188615B2 (en) 2016-06-10 2021-11-30 OneTrust, LLC Data processing consent capture systems and related methods
US11200341B2 (en) 2016-06-10 2021-12-14 OneTrust, LLC Consent receipt management systems and related methods
US11210420B2 (en) 2016-06-10 2021-12-28 OneTrust, LLC Data subject access request processing systems and related methods
US11222309B2 (en) 2016-06-10 2022-01-11 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11222142B2 (en) 2016-06-10 2022-01-11 OneTrust, LLC Data processing systems for validating authorization for personal data collection, storage, and processing
US11222139B2 (en) 2016-06-10 2022-01-11 OneTrust, LLC Data processing systems and methods for automatic discovery and assessment of mobile software development kits
US11227001B2 (en) 2017-01-31 2022-01-18 Experian Information Solutions, Inc. Massive scale heterogeneous data ingestion and user resolution
US11227247B2 (en) 2016-06-10 2022-01-18 OneTrust, LLC Data processing systems and methods for bundled privacy policies
US11228620B2 (en) 2016-06-10 2022-01-18 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11238390B2 (en) 2016-06-10 2022-02-01 OneTrust, LLC Privacy management systems and methods
US11244367B2 (en) * 2016-04-01 2022-02-08 OneTrust, LLC Data processing systems and methods for integrating privacy information management systems with data loss prevention tools or other tools for privacy design
US11277448B2 (en) 2016-06-10 2022-03-15 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11294939B2 (en) 2016-06-10 2022-04-05 OneTrust, LLC Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software
US11295316B2 (en) 2016-06-10 2022-04-05 OneTrust, LLC Data processing systems for identity validation for consumer rights requests and related methods
US11301796B2 (en) 2016-06-10 2022-04-12 OneTrust, LLC Data processing systems and methods for customizing privacy training
US11328092B2 (en) 2016-06-10 2022-05-10 OneTrust, LLC Data processing systems for processing and managing data subject access in a distributed environment
US11336697B2 (en) 2016-06-10 2022-05-17 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11343284B2 (en) 2016-06-10 2022-05-24 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US11341447B2 (en) 2016-06-10 2022-05-24 OneTrust, LLC Privacy management systems and methods
US11354434B2 (en) 2016-06-10 2022-06-07 OneTrust, LLC Data processing systems for verification of consent and notice processing and related methods
US11354435B2 (en) 2016-06-10 2022-06-07 OneTrust, LLC Data processing systems for data testing to confirm data deletion and related methods
US11366786B2 (en) 2016-06-10 2022-06-21 OneTrust, LLC Data processing systems for processing data subject access requests
US11366909B2 (en) 2016-06-10 2022-06-21 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11392720B2 (en) 2016-06-10 2022-07-19 OneTrust, LLC Data processing systems for verification of consent and notice processing and related methods
US11397819B2 (en) 2020-11-06 2022-07-26 OneTrust, LLC Systems and methods for identifying data processing activities based on data discovery results
US11403377B2 (en) 2016-06-10 2022-08-02 OneTrust, LLC Privacy management systems and methods
US11416590B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11416798B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing systems and methods for providing training in a vendor procurement process
US11416109B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Automated data processing systems and methods for automatically processing data subject access requests using a chatbot
US11416589B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11418492B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing systems and methods for using a data model to select a target data asset in a data migration
US11436373B2 (en) 2020-09-15 2022-09-06 OneTrust, LLC Data processing systems and methods for detecting tools for the automatic blocking of consent requests
US11438386B2 (en) 2016-06-10 2022-09-06 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11442906B2 (en) 2021-02-04 2022-09-13 OneTrust, LLC Managing custom attributes for domain objects defined within microservices
US11444976B2 (en) 2020-07-28 2022-09-13 OneTrust, LLC Systems and methods for automatically blocking the use of tracking tools
US11449797B1 (en) 2019-09-23 2022-09-20 Amazon Technologies, Inc. Secure machine learning workflow automation using isolated resources
US11461500B2 (en) 2016-06-10 2022-10-04 OneTrust, LLC Data processing systems for cookie compliance testing with website scanning and related methods
US11475165B2 (en) 2020-08-06 2022-10-18 OneTrust, LLC Data processing systems and methods for automatically redacting unstructured data from a data subject access request
US11475136B2 (en) 2016-06-10 2022-10-18 OneTrust, LLC Data processing systems for data transfer risk identification and related methods
US11481710B2 (en) 2016-06-10 2022-10-25 OneTrust, LLC Privacy management systems and methods
US11494515B2 (en) 2021-02-08 2022-11-08 OneTrust, LLC Data processing systems and methods for anonymizing data samples in classification analysis
US11520928B2 (en) 2016-06-10 2022-12-06 OneTrust, LLC Data processing systems for generating personal data receipts and related methods
US11526624B2 (en) 2020-09-21 2022-12-13 OneTrust, LLC Data processing systems and methods for automatically detecting target data transfers and target data processing
US11533315B2 (en) 2021-03-08 2022-12-20 OneTrust, LLC Data transfer discovery and analysis systems and related methods
US11546661B2 (en) 2021-02-18 2023-01-03 OneTrust, LLC Selective redaction of media content
US11544667B2 (en) 2016-06-10 2023-01-03 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11544409B2 (en) 2018-09-07 2023-01-03 OneTrust, LLC Data processing systems and methods for automatically protecting sensitive data within privacy management systems
US11562078B2 (en) 2021-04-16 2023-01-24 OneTrust, LLC Assessing and managing computational risk involved with integrating third party computing functionality within a computing system
US11562097B2 (en) 2016-06-10 2023-01-24 OneTrust, LLC Data processing systems for central consent repository and related methods
US11586700B2 (en) 2016-06-10 2023-02-21 OneTrust, LLC Data processing systems and methods for automatically blocking the use of tracking tools
US11601464B2 (en) 2021-02-10 2023-03-07 OneTrust, LLC Systems and methods for mitigating risks of third-party computing system functionality integration into a first-party computing system
US20230078396A1 (en) * 2018-09-06 2023-03-16 Linda M. Spulak System and method for the creation, management, and delivery of personal packets of information to be utilized as reverse cookies within network-based environments
US11620403B2 (en) 2019-01-11 2023-04-04 Experian Information Solutions, Inc. Systems and methods for secure data aggregation and computation
US11620142B1 (en) 2022-06-03 2023-04-04 OneTrust, LLC Generating and customizing user interfaces for demonstrating functions of interactive user environments
US11625502B2 (en) 2016-06-10 2023-04-11 OneTrust, LLC Data processing systems for identifying and modifying processes that are subject to data subject access requests
US11636171B2 (en) 2016-06-10 2023-04-25 OneTrust, LLC Data processing user interface monitoring systems and related methods
US11651104B2 (en) 2016-06-10 2023-05-16 OneTrust, LLC Consent receipt management systems and related methods
US11651106B2 (en) 2016-06-10 2023-05-16 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11651402B2 (en) 2016-04-01 2023-05-16 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of risk assessments
US11675929B2 (en) 2016-06-10 2023-06-13 OneTrust, LLC Data processing consent sharing systems and related methods
US11687528B2 (en) 2021-01-25 2023-06-27 OneTrust, LLC Systems and methods for discovery, classification, and indexing of data in a native computing system
US11727141B2 (en) 2016-06-10 2023-08-15 OneTrust, LLC Data processing systems and methods for synching privacy-related user consent across multiple computing devices
US11775348B2 (en) 2021-02-17 2023-10-03 OneTrust, LLC Managing custom workflows for domain objects defined within microservices
US11797528B2 (en) 2020-07-08 2023-10-24 OneTrust, LLC Systems and methods for targeted data discovery
US11880377B1 (en) 2021-03-26 2024-01-23 Experian Information Solutions, Inc. Systems and methods for entity resolution
US11941065B1 (en) 2019-09-13 2024-03-26 Experian Information Solutions, Inc. Single identifier platform for storing entity data
US11954225B1 (en) 2020-11-02 2024-04-09 Wells Fargo Bank, N.A. Data privacy management
US11962681B2 (en) 2023-04-04 2024-04-16 Experian Information Solutions, Inc. Symmetric encryption for private smart contracts among multiple parties in a private peer-to-peer network

Families Citing this family (82)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6942143B1 (en) * 1997-10-16 2005-09-13 Dentsu, Inc. System and method for accessing broadcast media in data communication with a broadcast receiving device
US6766946B2 (en) * 1997-10-16 2004-07-27 Dentsu, Inc. System for granting permission of user's personal information to third party
US6959420B1 (en) * 2001-11-30 2005-10-25 Microsoft Corporation Method and system for protecting internet users' privacy by evaluating web site platform for privacy preferences policy
US7266846B2 (en) * 2001-12-26 2007-09-04 United Services Automobile Association System and method of facilitating compliance with information sharing regulations
US7401352B2 (en) * 2002-08-30 2008-07-15 International Business Machines Corporation Secure system and method for enforcement of privacy policy and protection of confidentiality
US7207067B2 (en) * 2002-11-12 2007-04-17 Aol Llc Enforcing data protection legislation in Web data services
US20050076233A1 (en) * 2002-11-15 2005-04-07 Nokia Corporation Method and apparatus for transmitting data subject to privacy restrictions
US7334013B1 (en) 2002-12-20 2008-02-19 Microsoft Corporation Shared services management
US20040225616A1 (en) * 2003-05-09 2004-11-11 Arnold Gordon K. Method, system and computer program product for third-party verification of anonymous e-marketplace transactions using digital signatures
US7401233B2 (en) * 2003-06-24 2008-07-15 International Business Machines Corporation Method, system, and apparatus for dynamic data-driven privacy policy protection and data sharing
US20050005170A1 (en) * 2003-06-26 2005-01-06 International Business Machines Corporation Minimizing information gathered by access decision engines in access control systems
US20050055583A1 (en) * 2003-09-05 2005-03-10 Matsushita Electric Industrial Co., Ltd. Data management apparatus, data management method and program thereof
EP1668439A1 (en) * 2003-09-30 2006-06-14 British Telecommunications Public Limited Company Personalisation
US7206758B2 (en) * 2003-11-12 2007-04-17 International Business Machines Corporation Method, system and computer program product for identifying and implementing collected privacy policies as aggregate privacy policies in electronic transactions
US20050102194A1 (en) * 2003-11-12 2005-05-12 International Business Machines Corporation Method, system, and computer program product for filtering participants in electronic transactions using privacy policies
US7908208B2 (en) * 2003-12-10 2011-03-15 Alphacap Ventures Llc Private entity profile network
US9621539B2 (en) * 2004-01-30 2017-04-11 William H. Shawn Method and apparatus for securing the privacy of a computer network
US7623518B2 (en) * 2004-04-08 2009-11-24 Hewlett-Packard Development Company, L.P. Dynamic access control lists
US20050278333A1 (en) * 2004-05-26 2005-12-15 International Business Machines Corporation Method and system for managing privacy preferences
US7716242B2 (en) * 2004-10-19 2010-05-11 Oracle International Corporation Method and apparatus for controlling access to personally identifiable information
US8464311B2 (en) * 2004-10-28 2013-06-11 International Business Machines Corporation Method and system for implementing privacy notice, consent, and preference with a privacy proxy
US7797726B2 (en) * 2004-12-16 2010-09-14 International Business Machines Corporation Method and system for implementing privacy policy enforcement with a privacy proxy
US8561126B2 (en) * 2004-12-29 2013-10-15 International Business Machines Corporation Automatic enforcement of obligations according to a data-handling policy
US8225376B2 (en) * 2006-07-25 2012-07-17 Facebook, Inc. Dynamically generating a privacy summary
US9459622B2 (en) 2007-01-12 2016-10-04 Legalforce, Inc. Driverless vehicle commerce network and community
US9064288B2 (en) 2006-03-17 2015-06-23 Fatdoor, Inc. Government structures and neighborhood leads in a geo-spatial environment
US9098545B2 (en) 2007-07-10 2015-08-04 Raj Abhyanker Hot news neighborhood banter in a geo-spatial social network
US8965409B2 (en) 2006-03-17 2015-02-24 Fatdoor, Inc. User-generated community publication in an online neighborhood social network
US9373149B2 (en) 2006-03-17 2016-06-21 Fatdoor, Inc. Autonomous neighborhood vehicle commerce network and community
US9002754B2 (en) 2006-03-17 2015-04-07 Fatdoor, Inc. Campaign in a geo-spatial environment
US9070101B2 (en) 2007-01-12 2015-06-30 Fatdoor, Inc. Peer-to-peer neighborhood delivery multi-copter and method
US9037516B2 (en) 2006-03-17 2015-05-19 Fatdoor, Inc. Direct mailing in a geo-spatial environment
US9071367B2 (en) 2006-03-17 2015-06-30 Fatdoor, Inc. Emergency including crime broadcast in a neighborhood social network
US7912762B2 (en) 2006-03-31 2011-03-22 Amazon Technologies, Inc. Customizable sign-on service
US20080086765A1 (en) * 2006-10-05 2008-04-10 Microsoft Corporation Issuance privacy
US8032472B2 (en) * 2007-04-04 2011-10-04 Tuen Solutions Limited Liability Company Intelligent agent for distributed services for mobile devices
US20080300897A1 (en) * 2007-06-01 2008-12-04 Rafael Gazetov Business method for domain name creation and marketing
JP5046158B2 (en) * 2007-08-10 2012-10-10 インターナショナル・ビジネス・マシーンズ・コーポレーション Apparatus and method for detecting characteristics of an e-mail message
US20090112706A1 (en) * 2007-10-24 2009-04-30 Uab "Ieec" Business method for compound attributes creation and marketing
US20090157452A1 (en) * 2007-12-17 2009-06-18 American Express Travel Related Services Company, Inc. Policy and contract compliance system and method
US20090222879A1 (en) * 2008-03-03 2009-09-03 Microsoft Corporation Super policy in information protection systems
US20090319377A1 (en) * 2008-05-14 2009-12-24 Uab "Ieec" Business method for self promotion and marketing
US8316451B2 (en) * 2008-06-21 2012-11-20 Microsoft Corporation Presenting privacy policy in a network environment responsive to user preference
US20090320092A1 (en) * 2008-06-24 2009-12-24 Microsoft Corporation User interface for managing access to a health-record
US20100017218A1 (en) * 2008-07-21 2010-01-21 Uab "Ieec" Business method for domain name and trade mark assigning and marketing
EP2175609A1 (en) * 2008-10-09 2010-04-14 Alcatel Lucent User-assisted privacy data management system in a multi-service environment
US20100324968A1 (en) * 2009-06-19 2010-12-23 Roland Schoettle System and method for automatically restructuring database entries based on data obtained among a plurality of users
US8311893B2 (en) * 2009-06-19 2012-11-13 Roland Schoettle System and method for providing information on selected topics to interested users
US8977853B2 (en) * 2010-01-06 2015-03-10 Telcordia Technologies, Inc. System and method establishing trusted relationships to enable secure exchange of private information
US20110270768A1 (en) * 2010-04-30 2011-11-03 Bank Of America Corporation International Cross Border Data Movement
US20110283335A1 (en) * 2010-05-12 2011-11-17 Microsoft Corporation Handling privacy preferences and policies through logic language
US9064236B2 (en) 2011-02-02 2015-06-23 Tvonfly Solutions Llp Business method for aggregation and presentation of the media data
JP5939248B2 (en) * 2011-03-03 2016-06-22 日本電気株式会社 Policy arbitration method, arbitration server, and program
JP5917713B2 (en) * 2011-12-30 2016-05-18 インテル・コーポレーション Cloud-based real-time APP privacy dashboard
EP2755158A1 (en) * 2013-01-09 2014-07-16 Thomson Licensing Method and device for privacy-respecting data processing
US20140324716A1 (en) * 2013-04-29 2014-10-30 Carolina Haber Florencio Method and system for deterring product counterfeiting
GB2521478B (en) * 2013-12-23 2022-02-02 Arm Ip Ltd Control of data provision
US9439367B2 (en) 2014-02-07 2016-09-13 Arthi Abhyanker Network enabled gardening with a remotely controllable positioning extension
US9457901B2 (en) 2014-04-22 2016-10-04 Fatdoor, Inc. Quadcopter with a printable payload extension system and method
US9004396B1 (en) 2014-04-24 2015-04-14 Fatdoor, Inc. Skyteboard quadcopter and method
US9022324B1 (en) 2014-05-05 2015-05-05 Fatdoor, Inc. Coordination of aerial vehicles through a central server
US20170091412A1 (en) 2014-05-30 2017-03-30 Apple Inc. Systems and Methods for Facilitating Health Research Using a Personal Wearable Device With Multiple Pairing Configurations
US11404146B2 (en) * 2014-05-30 2022-08-02 Apple Inc. Managing user information—data type extension
US9971985B2 (en) 2014-06-20 2018-05-15 Raj Abhyanker Train based community
US9441981B2 (en) 2014-06-20 2016-09-13 Fatdoor, Inc. Variable bus stops across a bus route in a regional transportation network
US9451020B2 (en) 2014-07-18 2016-09-20 Legalforce, Inc. Distributed communication of independent autonomous vehicles to provide redundancy and performance
US20160044039A1 (en) * 2014-08-07 2016-02-11 Alcatel Lucent Privacy-aware personal data store
US20170068827A1 (en) * 2015-09-04 2017-03-09 Swim.IT Inc. Live privacy policy method and apparatus
US10025689B2 (en) * 2016-01-22 2018-07-17 International Business Machines Corporation Enhanced policy editor with completion support and on demand validation
US10747902B2 (en) * 2016-05-25 2020-08-18 Atomite, Inc. System and method of efficient and secure data filtering of non-permitted data
US9998453B1 (en) * 2016-06-10 2018-06-12 Amazon Technologies, Inc. Controlling access to personal data
US11009886B2 (en) 2017-05-12 2021-05-18 Autonomy Squared Llc Robot pickup method
JP2021103342A (en) * 2018-04-02 2021-07-15 ソニーグループ株式会社 Information processing device, information processing method, and program
US10255415B1 (en) * 2018-04-03 2019-04-09 Palantir Technologies Inc. Controlling access to computer resources
KR102312916B1 (en) * 2018-05-07 2021-10-15 구글 엘엘씨 Data Collection Consent Tool
US11074368B2 (en) 2018-10-15 2021-07-27 International Business Machines Corporation Obfuscation and routing of sensitive actions or requests based on social connections
US20200193454A1 (en) * 2018-12-12 2020-06-18 Qingfeng Zhao Method and Apparatus for Generating Target Audience Data
US11120160B2 (en) * 2019-05-31 2021-09-14 Advanced New Technologies Co., Ltd. Distributed personal data storage and encrypted personal data service based on secure computation
CN110210246B (en) * 2019-05-31 2022-01-07 创新先进技术有限公司 Personal data service method and system based on safety calculation
US11343255B2 (en) 2019-06-28 2022-05-24 EMC IP Holding Company LLC Security policy exchange and enforcement for question delegation environments
US11258603B2 (en) * 2019-07-31 2022-02-22 EMC IP Holding Company LLC Access controls for question delegation environments
EP3975498A1 (en) * 2020-09-28 2022-03-30 Tata Consultancy Services Limited Method and system for sequencing asset segments of privacy policy

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6253203B1 (en) * 1998-10-02 2001-06-26 Ncr Corporation Privacy-enhanced database
US6275824B1 (en) * 1998-10-02 2001-08-14 Ncr Corporation System and method for managing data privacy in a database management system
US20010054155A1 (en) * 1999-12-21 2001-12-20 Thomas Hagan Privacy and security method and system for a World-Wide-Web site
US20020010784A1 (en) * 2000-01-06 2002-01-24 Clayton Gary E. Policy notice method and system
US20020029254A1 (en) * 2000-09-06 2002-03-07 Davis Terry L. Method and system for managing personal information
US20020087472A1 (en) * 2000-12-29 2002-07-04 Walter Joanne S. Data privacy encoding for consumer input media
US20020091741A1 (en) * 2001-01-05 2002-07-11 Microsoft Corporation Method of removing personal information from an electronic document
US6480850B1 (en) * 1998-10-02 2002-11-12 Ncr Corporation System and method for managing data privacy in a database management system including a dependently connected privacy data mart

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6253203B1 (en) * 1998-10-02 2001-06-26 Ncr Corporation Privacy-enhanced database
US6275824B1 (en) * 1998-10-02 2001-08-14 Ncr Corporation System and method for managing data privacy in a database management system
US6480850B1 (en) * 1998-10-02 2002-11-12 Ncr Corporation System and method for managing data privacy in a database management system including a dependently connected privacy data mart
US20010054155A1 (en) * 1999-12-21 2001-12-20 Thomas Hagan Privacy and security method and system for a World-Wide-Web site
US20020010784A1 (en) * 2000-01-06 2002-01-24 Clayton Gary E. Policy notice method and system
US20020029254A1 (en) * 2000-09-06 2002-03-07 Davis Terry L. Method and system for managing personal information
US20020087472A1 (en) * 2000-12-29 2002-07-04 Walter Joanne S. Data privacy encoding for consumer input media
US20020091741A1 (en) * 2001-01-05 2002-07-11 Microsoft Corporation Method of removing personal information from an electronic document

Non-Patent Citations (11)

* Cited by examiner, † Cited by third party
Title
Brodia Personal Commerce Manager pp. 1.
IDcide-PrivacyWal Site Monitor pp. 1-2.
IDcide-PrivacyWall Site Analyzer pp. 1-2.
Lumeria-SuperProfile. What is a Superprofile pp. 1.
Microsoft .Net My Services pp. 1-11.
Novell. Digitalme Making Life Easier on the Net pp. 1-3.
PentaSafe Security Technologies, Inc. pp. 1-4.
Persona-(p)-CRM Internet Marketing Platform pp. 1.
PrivacyRight Products pp. 1.
Tivoli Privacy Manager pp. 1-2.
Zeroknowledge-Freedom Internet privacy and Security Software pp. 1-3.

Cited By (443)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7962962B2 (en) 2001-06-19 2011-06-14 International Business Machines Corporation Using an object model to improve handling of personally identifiable information
US20030004734A1 (en) * 2001-06-19 2003-01-02 International Business Machines Corporation Using an object model to improve handling of personally identifiable information
US20110119732A1 (en) * 2002-02-27 2011-05-19 Microsoft Corporation System and method for user-centric authorization to access user-specific information
US8185932B2 (en) * 2002-02-27 2012-05-22 Microsoft Corporation System and method for user-centric authorization to access user-specific information
US20100145840A1 (en) * 2003-03-21 2010-06-10 Mighty Net, Inc. Card management system and method
US8781953B2 (en) 2003-03-21 2014-07-15 Consumerinfo.Com, Inc. Card management system and method
US7966663B2 (en) * 2003-05-20 2011-06-21 United States Postal Service Methods and systems for determining privacy requirements for an information resource
US20050132188A1 (en) * 2003-05-20 2005-06-16 Khin Peter M. Methods and systems for determining security requirements for an information resource
US20080028435A1 (en) * 2003-05-20 2008-01-31 Strickland Zoe C C Methods and systems for determining privacy requirements for an informatin resource
US8046819B2 (en) 2003-05-20 2011-10-25 United States Postal Service Methods and systems for determining security requirements for an information resource
US10003667B2 (en) 2004-02-23 2018-06-19 Microsoft Technology Licensing, Llc Profile and consent accrual
US8719366B2 (en) 2004-02-23 2014-05-06 Ashvin Joseph Mathew Profile and consent accrual
US20090300509A1 (en) * 2004-02-23 2009-12-03 Microsoft Corporation Profile and consent accrual
US9092637B2 (en) 2004-02-23 2015-07-28 Microsoft Technology Licensing, Llc Profile and consent accrual
US20060111874A1 (en) * 2004-09-30 2006-05-25 Blazant, Inx. Method and system for filtering, organizing and presenting selected information technology information as a function of business dimensions
US8175889B1 (en) 2005-04-06 2012-05-08 Experian Information Solutions, Inc. Systems and methods for tracking changes of address based on service disconnect/connect data
US20070282982A1 (en) * 2006-06-05 2007-12-06 Rhonda Childress Policy-Based Management in a Computer Environment
US10437895B2 (en) 2007-03-30 2019-10-08 Consumerinfo.Com, Inc. Systems and methods for data verification
US11308170B2 (en) 2007-03-30 2022-04-19 Consumerinfo.Com, Inc. Systems and methods for data verification
US9342783B1 (en) 2007-03-30 2016-05-17 Consumerinfo.Com, Inc. Systems and methods for data verification
US20080256643A1 (en) * 2007-04-13 2008-10-16 Microsoft Corporation Multiple entity authorization model
US8327456B2 (en) * 2007-04-13 2012-12-04 Microsoft Corporation Multiple entity authorization model
US20080313154A1 (en) * 2007-06-12 2008-12-18 At&T Delaware Intellectual Property, Inc. Method and apparatus for managing contact information
US20090100136A1 (en) * 2007-10-15 2009-04-16 Sony Ericsson Mobile Communications Ab Intelligent presence
US20090106815A1 (en) * 2007-10-23 2009-04-23 International Business Machines Corporation Method for mapping privacy policies to classification labels
US8984584B1 (en) 2008-05-27 2015-03-17 Open Invention Network, Llc System integrating an identity selector and user-portable device and method of use in a user-centric identity management system
US9203867B1 (en) 2008-05-27 2015-12-01 Open Invention Network, Llc User-directed privacy control in a user-centric identity management system
US9130915B2 (en) 2008-05-27 2015-09-08 Open Invention Network, Llc Preference editor to facilitate privacy controls over user identities
US9178864B1 (en) 2008-05-27 2015-11-03 Open Invention Network, Llc User-portable device and method of use in a user-centric identity management system
US9407623B1 (en) * 2008-05-27 2016-08-02 Open Invention Network Llc System integrating an identity selector and user-portable device and method of use in a user-centric identity management system
US20090300714A1 (en) * 2008-05-27 2009-12-03 Open Invention Network Llc Privacy engine and method of use in a user-centric identity management system
US20090300512A1 (en) * 2008-05-27 2009-12-03 Open Invention Network Llc Preference editor to facilitate privacy controls over user identities
US10298568B1 (en) * 2008-05-27 2019-05-21 Open Invention Network Llc System integrating an identity selector and user-portable device and method of use in a user-centric identity management system
US9338188B1 (en) 2008-05-27 2016-05-10 Open Invention Network, Llc User agent to exercise privacy control management in a user-centric identity management system
US10075446B2 (en) 2008-06-26 2018-09-11 Experian Marketing Solutions, Inc. Systems and methods for providing an integrated identifier
US11157872B2 (en) 2008-06-26 2021-10-26 Experian Marketing Solutions, Llc Systems and methods for providing an integrated identifier
US11769112B2 (en) 2008-06-26 2023-09-26 Experian Marketing Solutions, Llc Systems and methods for providing an integrated identifier
US11636540B1 (en) 2008-08-14 2023-04-25 Experian Information Solutions, Inc. Multi-bureau credit file freeze and unfreeze
US10650448B1 (en) 2008-08-14 2020-05-12 Experian Information Solutions, Inc. Multi-bureau credit file freeze and unfreeze
US9256904B1 (en) 2008-08-14 2016-02-09 Experian Information Solutions, Inc. Multi-bureau credit file freeze and unfreeze
US11004147B1 (en) 2008-08-14 2021-05-11 Experian Information Solutions, Inc. Multi-bureau credit file freeze and unfreeze
US10115155B1 (en) 2008-08-14 2018-10-30 Experian Information Solution, Inc. Multi-bureau credit file freeze and unfreeze
US9792648B1 (en) 2008-08-14 2017-10-17 Experian Information Solutions, Inc. Multi-bureau credit file freeze and unfreeze
US9489694B2 (en) 2008-08-14 2016-11-08 Experian Information Solutions, Inc. Multi-bureau credit file freeze and unfreeze
US20110060905A1 (en) * 2009-05-11 2011-03-10 Experian Marketing Solutions, Inc. Systems and methods for providing anonymized user profile data
US8966649B2 (en) 2009-05-11 2015-02-24 Experian Marketing Solutions, Inc. Systems and methods for providing anonymized user profile data
US9595051B2 (en) 2009-05-11 2017-03-14 Experian Marketing Solutions, Inc. Systems and methods for providing anonymized user profile data
US8639920B2 (en) 2009-05-11 2014-01-28 Experian Marketing Solutions, Inc. Systems and methods for providing anonymized user profile data
US20110219423A1 (en) * 2010-03-05 2011-09-08 Nokia Corporation Method and apparatus for triggering user communications based on privacy information
US10909617B2 (en) 2010-03-24 2021-02-02 Consumerinfo.Com, Inc. Indirect monitoring and reporting of a user's credit data
US20110252226A1 (en) * 2010-04-10 2011-10-13 Max Planck Gesellschaft Zur Foerderung Der Wissenschaften Preserving user privacy in response to user interactions
US8931058B2 (en) 2010-07-01 2015-01-06 Experian Information Solutions, Inc. Systems and methods for permission arbitrated transaction services
US8744956B1 (en) 2010-07-01 2014-06-03 Experian Information Solutions, Inc. Systems and methods for permission arbitrated transaction services
US10417704B2 (en) 2010-11-02 2019-09-17 Experian Technology Ltd. Systems and methods of assisted strategy design
US8478674B1 (en) 2010-11-12 2013-07-02 Consumerinfo.Com, Inc. Application clusters
US8818888B1 (en) 2010-11-12 2014-08-26 Consumerinfo.Com, Inc. Application clusters
US9684905B1 (en) 2010-11-22 2017-06-20 Experian Information Solutions, Inc. Systems and methods for data verification
US9147042B1 (en) 2010-11-22 2015-09-29 Experian Information Solutions, Inc. Systems and methods for data verification
US8595857B2 (en) * 2010-12-28 2013-11-26 Verizon Patent And Licensing Inc. Persona-based identity management system
US20120167234A1 (en) * 2010-12-28 2012-06-28 Verizon Patent And Licensing, Inc. Persona-based identity management system
US9558519B1 (en) 2011-04-29 2017-01-31 Consumerinfo.Com, Inc. Exposing reporting cycle information
US11861691B1 (en) 2011-04-29 2024-01-02 Consumerinfo.Com, Inc. Exposing reporting cycle information
US9665854B1 (en) 2011-06-16 2017-05-30 Consumerinfo.Com, Inc. Authentication alerts
US11954655B1 (en) 2011-06-16 2024-04-09 Consumerinfo.Com, Inc. Authentication alerts
US10115079B1 (en) 2011-06-16 2018-10-30 Consumerinfo.Com, Inc. Authentication alerts
US10685336B1 (en) 2011-06-16 2020-06-16 Consumerinfo.Com, Inc. Authentication alerts
US11232413B1 (en) 2011-06-16 2022-01-25 Consumerinfo.Com, Inc. Authentication alerts
US9607336B1 (en) 2011-06-16 2017-03-28 Consumerinfo.Com, Inc. Providing credit inquiry alerts
US10719873B1 (en) 2011-06-16 2020-07-21 Consumerinfo.Com, Inc. Providing credit inquiry alerts
US10061936B1 (en) 2011-09-16 2018-08-28 Consumerinfo.Com, Inc. Systems and methods of identity protection and management
US11790112B1 (en) 2011-09-16 2023-10-17 Consumerinfo.Com, Inc. Systems and methods of identity protection and management
US11087022B2 (en) 2011-09-16 2021-08-10 Consumerinfo.Com, Inc. Systems and methods of identity protection and management
US10642999B2 (en) 2011-09-16 2020-05-05 Consumerinfo.Com, Inc. Systems and methods of identity protection and management
US9542553B1 (en) 2011-09-16 2017-01-10 Consumerinfo.Com, Inc. Systems and methods of identity protection and management
US11568348B1 (en) 2011-10-31 2023-01-31 Consumerinfo.Com, Inc. Pre-data breach monitoring
US11030562B1 (en) 2011-10-31 2021-06-08 Consumerinfo.Com, Inc. Pre-data breach monitoring
US8646032B2 (en) * 2011-12-30 2014-02-04 Nokia Corporation Method and apparatus providing privacy setting and monitoring user interface
US20130174211A1 (en) * 2011-12-30 2013-07-04 Nokia Corporation Method And Apparatus Providing Privacy Setting And Monitoring User Interface
US9081986B2 (en) 2012-05-07 2015-07-14 Nokia Technologies Oy Method and apparatus for user information exchange
US9059963B2 (en) * 2012-06-08 2015-06-16 MyClassicGarage, LLC Method and system for storage and selective sharing of vehicle data
US20130332578A1 (en) * 2012-06-08 2013-12-12 MyClassicGarage, LLC Method and System for Storage and Selective Sharing of Vehicle Data
US9277364B2 (en) 2012-06-25 2016-03-01 Nokia Technologies Oy Methods and apparatus for reporting location privacy
US10360352B2 (en) 2012-10-02 2019-07-23 Banjo, Inc. System and method for event-based vehicle operation
US9934368B2 (en) 2012-10-02 2018-04-03 Banjo, Inc. User-generated content permissions status analysis system and method
US10331863B2 (en) 2012-10-02 2019-06-25 Banjo, Inc. User-generated content permissions status analysis system and method
US9881179B2 (en) 2012-10-02 2018-01-30 Banjo, Inc. User-generated content permissions status analysis system and method
US10678815B2 (en) 2012-10-02 2020-06-09 Banjo, Inc. Dynamic event detection system and method
US20160034712A1 (en) * 2012-10-02 2016-02-04 Banjo, Inc. System and method for event-related content discovery, curation, and presentation
US9652525B2 (en) 2012-10-02 2017-05-16 Banjo, Inc. Dynamic event detection system and method
US8893297B2 (en) 2012-11-21 2014-11-18 Solomo Identity, Llc Personal data management system with sharing revocation
US9092796B2 (en) 2012-11-21 2015-07-28 Solomo Identity, Llc. Personal data management system with global data store
US8856894B1 (en) 2012-11-28 2014-10-07 Consumerinfo.Com, Inc. Always on authentication
US10255598B1 (en) 2012-12-06 2019-04-09 Consumerinfo.Com, Inc. Credit card account data extraction
US9697263B1 (en) 2013-03-04 2017-07-04 Experian Information Solutions, Inc. Consumer data request fulfillment system
US11164271B2 (en) 2013-03-15 2021-11-02 Csidentity Corporation Systems and methods of delayed authentication and billing for on-demand products
US9633322B1 (en) 2013-03-15 2017-04-25 Consumerinfo.Com, Inc. Adjustment of knowledge-based authentication
US10169761B1 (en) 2013-03-15 2019-01-01 ConsumerInfo.com Inc. Adjustment of knowledge-based authentication
US10664936B2 (en) 2013-03-15 2020-05-26 Csidentity Corporation Authentication systems and methods for on-demand products
US10740762B2 (en) 2013-03-15 2020-08-11 Consumerinfo.Com, Inc. Adjustment of knowledge-based authentication
US11790473B2 (en) 2013-03-15 2023-10-17 Csidentity Corporation Systems and methods of delayed authentication and billing for on-demand products
US11288677B1 (en) 2013-03-15 2022-03-29 Consumerlnfo.com, Inc. Adjustment of knowledge-based authentication
US11775979B1 (en) 2013-03-15 2023-10-03 Consumerinfo.Com, Inc. Adjustment of knowledge-based authentication
US10453159B2 (en) 2013-05-23 2019-10-22 Consumerinfo.Com, Inc. Digital identity
US9721147B1 (en) 2013-05-23 2017-08-01 Consumerinfo.Com, Inc. Digital identity
US11803929B1 (en) 2013-05-23 2023-10-31 Consumerinfo.Com, Inc. Digital identity
US11120519B2 (en) 2013-05-23 2021-09-14 Consumerinfo.Com, Inc. Digital identity
US10102536B1 (en) 2013-11-15 2018-10-16 Experian Information Solutions, Inc. Micro-geographic aggregation system
US10580025B2 (en) 2013-11-15 2020-03-03 Experian Information Solutions, Inc. Micro-geographic aggregation system
US9529851B1 (en) 2013-12-02 2016-12-27 Experian Information Solutions, Inc. Server architecture for electronic data quality processing
US11847693B1 (en) 2014-02-14 2023-12-19 Experian Information Solutions, Inc. Automatic generation of code for attributes
US10262362B1 (en) 2014-02-14 2019-04-16 Experian Information Solutions, Inc. Automatic generation of code for attributes
US11107158B1 (en) 2014-02-14 2021-08-31 Experian Information Solutions, Inc. Automatic generation of code for attributes
US10963579B2 (en) 2014-02-21 2021-03-30 Lens Ventures, Llc Management of data privacy and security in a pervasive computing environment
US10839089B2 (en) 2014-02-21 2020-11-17 Lens Ventures, Llc Management of drone operations and security in a pervasive computing environment
US10121015B2 (en) * 2014-02-21 2018-11-06 Lens Ventures, Llc Management of data privacy and security in a pervasive computing environment
US10373240B1 (en) 2014-04-25 2019-08-06 Csidentity Corporation Systems, methods and computer-program products for eligibility verification
US11074641B1 (en) 2014-04-25 2021-07-27 Csidentity Corporation Systems, methods and computer-program products for eligibility verification
US11587150B1 (en) 2014-04-25 2023-02-21 Csidentity Corporation Systems and methods for eligibility verification
US10289867B2 (en) 2014-07-27 2019-05-14 OneTrust, LLC Data processing systems for webform crawling to map processing activities and related methods
US9817997B2 (en) 2014-12-18 2017-11-14 Banjo, Inc. User-generated content permissions status analysis system and method
US11729230B1 (en) 2015-11-24 2023-08-15 Experian Information Solutions, Inc. Real-time event-based notification system
US10757154B1 (en) 2015-11-24 2020-08-25 Experian Information Solutions, Inc. Real-time event-based notification system
US11159593B1 (en) 2015-11-24 2021-10-26 Experian Information Solutions, Inc. Real-time event-based notification system
US10853859B2 (en) * 2016-04-01 2020-12-01 OneTrust, LLC Data processing systems and methods for operationalizing privacy compliance and assessing the risk of various respective privacy campaigns
US10706447B2 (en) 2016-04-01 2020-07-07 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US10956952B2 (en) * 2016-04-01 2021-03-23 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US9892442B2 (en) 2016-04-01 2018-02-13 OneTrust, LLC Data processing systems and methods for efficiently assessing the risk of privacy campaigns
US9892441B2 (en) 2016-04-01 2018-02-13 OneTrust, LLC Data processing systems and methods for operationalizing privacy compliance and assessing the risk of various respective privacy campaigns
US9892444B2 (en) 2016-04-01 2018-02-13 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US9892443B2 (en) 2016-04-01 2018-02-13 OneTrust, LLC Data processing systems for modifying privacy campaign data via electronic messaging systems
US9898769B2 (en) 2016-04-01 2018-02-20 OneTrust, LLC Data processing systems and methods for operationalizing privacy compliance via integrated mobile applications
US10176503B2 (en) 2016-04-01 2019-01-08 OneTrust, LLC Data processing systems and methods for efficiently assessing the risk of privacy campaigns
US10169788B2 (en) 2016-04-01 2019-01-01 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US11004125B2 (en) * 2016-04-01 2021-05-11 OneTrust, LLC Data processing systems and methods for integrating privacy information management systems with data loss prevention tools or other tools for privacy design
US9892477B2 (en) 2016-04-01 2018-02-13 OneTrust, LLC Data processing systems and methods for implementing audit schedules for privacy campaigns
US10176502B2 (en) 2016-04-01 2019-01-08 OneTrust, LLC Data processing systems and methods for integrating privacy information management systems with data loss prevention tools or other tools for privacy design
US10423996B2 (en) 2016-04-01 2019-09-24 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US10169790B2 (en) 2016-04-01 2019-01-01 OneTrust, LLC Data processing systems and methods for operationalizing privacy compliance via integrated mobile applications
US10026110B2 (en) 2016-04-01 2018-07-17 OneTrust, LLC Data processing systems and methods for generating personal data inventories for organizations and other entities
US9691090B1 (en) * 2016-04-01 2017-06-27 OneTrust, LLC Data processing systems and methods for operationalizing privacy compliance and assessing the risk of various respective privacy campaigns
US10169789B2 (en) 2016-04-01 2019-01-01 OneTrust, LLC Data processing systems for modifying privacy campaign data via electronic messaging systems
US11651402B2 (en) 2016-04-01 2023-05-16 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of risk assessments
US20200126134A1 (en) * 2016-04-01 2020-04-23 OneTrust, LLC Data processing systems and methods for operationalizing privacy compliance and assessing the risk of various respective privacy campaigns
US20200126133A1 (en) * 2016-04-01 2020-04-23 OneTrust, LLC Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments
US11244367B2 (en) * 2016-04-01 2022-02-08 OneTrust, LLC Data processing systems and methods for integrating privacy information management systems with data loss prevention tools or other tools for privacy design
US10803200B2 (en) 2016-06-10 2020-10-13 OneTrust, LLC Data processing systems for processing and managing data subject access in a distributed environment
US11138299B2 (en) 2016-06-10 2021-10-05 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US10452864B2 (en) 2016-06-10 2019-10-22 OneTrust, LLC Data processing systems for webform crawling to map processing activities and related methods
US10445526B2 (en) 2016-06-10 2019-10-15 OneTrust, LLC Data processing systems for measuring privacy maturity within an organization
US10454973B2 (en) 2016-06-10 2019-10-22 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10467432B2 (en) 2016-06-10 2019-11-05 OneTrust, LLC Data processing systems for use in automatically generating, populating, and submitting data subject access requests
US10496803B2 (en) 2016-06-10 2019-12-03 OneTrust, LLC Data processing systems and methods for efficiently assessing the risk of privacy campaigns
US10496846B1 (en) 2016-06-10 2019-12-03 OneTrust, LLC Data processing and communications systems and methods for the efficient implementation of privacy by design
US10498770B2 (en) 2016-06-10 2019-12-03 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10503926B2 (en) 2016-06-10 2019-12-10 OneTrust, LLC Consent receipt management systems and related methods
US10510031B2 (en) 2016-06-10 2019-12-17 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US10509894B2 (en) 2016-06-10 2019-12-17 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US10509920B2 (en) 2016-06-10 2019-12-17 OneTrust, LLC Data processing systems for processing data subject access requests
US10558821B2 (en) 2016-06-10 2020-02-11 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10567439B2 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10565161B2 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for processing data subject access requests
US10564935B2 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for integration of consumer feedback with data subject access requests and related methods
US10564936B2 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for identity validation of data subject access requests and related methods
US10565236B1 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10565397B1 (en) 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10572686B2 (en) 2016-06-10 2020-02-25 OneTrust, LLC Consent receipt management systems and related methods
US10574705B2 (en) 2016-06-10 2020-02-25 OneTrust, LLC Data processing and scanning systems for generating and populating a data inventory
US10437860B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10586075B2 (en) 2016-06-10 2020-03-10 OneTrust, LLC Data processing systems for orphaned data identification and deletion and related methods
US10585968B2 (en) 2016-06-10 2020-03-10 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10586072B2 (en) 2016-06-10 2020-03-10 OneTrust, LLC Data processing systems for measuring privacy maturity within an organization
US10592648B2 (en) 2016-06-10 2020-03-17 OneTrust, LLC Consent receipt management systems and related methods
US10592692B2 (en) 2016-06-10 2020-03-17 OneTrust, LLC Data processing systems for central consent repository and related methods
US10594740B2 (en) 2016-06-10 2020-03-17 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10599870B2 (en) 2016-06-10 2020-03-24 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US10606916B2 (en) 2016-06-10 2020-03-31 OneTrust, LLC Data processing user interface monitoring systems and related methods
US10607028B2 (en) 2016-06-10 2020-03-31 OneTrust, LLC Data processing systems for data testing to confirm data deletion and related methods
US10614247B2 (en) 2016-06-10 2020-04-07 OneTrust, LLC Data processing systems for automated classification of personal information from documents and related methods
US10614246B2 (en) 2016-06-10 2020-04-07 OneTrust, LLC Data processing systems and methods for auditing data request compliance
US10437412B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Consent receipt management systems and related methods
US10438016B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10438020B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Data processing systems for generating and populating a data inventory for processing data access requests
US10642870B2 (en) 2016-06-10 2020-05-05 OneTrust, LLC Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software
US10440062B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Consent receipt management systems and related methods
US10438017B2 (en) 2016-06-10 2019-10-08 OneTrust, LLC Data processing systems for processing data subject access requests
US10678945B2 (en) 2016-06-10 2020-06-09 OneTrust, LLC Consent receipt management systems and related methods
US10430740B2 (en) 2016-06-10 2019-10-01 One Trust, LLC Data processing systems for calculating and communicating cost of fulfilling data subject access requests and related methods
US20200186572A1 (en) * 2016-06-10 2020-06-11 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10685140B2 (en) 2016-06-10 2020-06-16 OneTrust, LLC Consent receipt management systems and related methods
US10416966B2 (en) 2016-06-10 2019-09-17 OneTrust, LLC Data processing systems for identity validation of data subject access requests and related methods
US10692033B2 (en) 2016-06-10 2020-06-23 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US10706176B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data-processing consent refresh, re-prompt, and recapture systems and related methods
US10417450B2 (en) 2016-06-10 2019-09-17 OneTrust, LLC Data processing systems for prioritizing data subject access requests for fulfillment and related methods
US10705801B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data processing systems for identity validation of data subject access requests and related methods
US10706379B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data processing systems for automatic preparation for remediation and related methods
US10708305B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Automated data processing systems and methods for automatically processing requests for privacy-related information
US10706174B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data processing systems for prioritizing data subject access requests for fulfillment and related methods
US10706131B2 (en) 2016-06-10 2020-07-07 OneTrust, LLC Data processing systems and methods for efficiently assessing the risk of privacy campaigns
US10713387B2 (en) 2016-06-10 2020-07-14 OneTrust, LLC Consent conversion optimization systems and related methods
US10419493B2 (en) 2016-06-10 2019-09-17 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10726158B2 (en) 2016-06-10 2020-07-28 OneTrust, LLC Consent receipt management and automated process blocking systems and related methods
US9729583B1 (en) 2016-06-10 2017-08-08 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10740487B2 (en) 2016-06-10 2020-08-11 OneTrust, LLC Data processing systems and methods for populating and maintaining a centralized database of personal data
US11921894B2 (en) 2016-06-10 2024-03-05 OneTrust, LLC Data processing systems for generating and populating a data inventory for processing data access requests
US10754981B2 (en) 2016-06-10 2020-08-25 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10353673B2 (en) 2016-06-10 2019-07-16 OneTrust, LLC Data processing systems for integration of consumer feedback with data subject access requests and related methods
US10762236B2 (en) 2016-06-10 2020-09-01 OneTrust, LLC Data processing user interface monitoring systems and related methods
US10769302B2 (en) 2016-06-10 2020-09-08 OneTrust, LLC Consent receipt management systems and related methods
US10769303B2 (en) 2016-06-10 2020-09-08 OneTrust, LLC Data processing systems for central consent repository and related methods
US10769301B2 (en) 2016-06-10 2020-09-08 OneTrust, LLC Data processing systems for webform crawling to map processing activities and related methods
US10776515B2 (en) 2016-06-10 2020-09-15 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10776518B2 (en) 2016-06-10 2020-09-15 OneTrust, LLC Consent receipt management systems and related methods
US10776517B2 (en) 2016-06-10 2020-09-15 OneTrust, LLC Data processing systems for calculating and communicating cost of fulfilling data subject access requests and related methods
US10776514B2 (en) 2016-06-10 2020-09-15 OneTrust, LLC Data processing systems for the identification and deletion of personal data in computer systems
US10783256B2 (en) 2016-06-10 2020-09-22 OneTrust, LLC Data processing systems for data transfer risk identification and related methods
US10791150B2 (en) 2016-06-10 2020-09-29 OneTrust, LLC Data processing and scanning systems for generating and populating a data inventory
US10798133B2 (en) 2016-06-10 2020-10-06 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10796020B2 (en) 2016-06-10 2020-10-06 OneTrust, LLC Consent receipt management systems and related methods
US10796260B2 (en) 2016-06-10 2020-10-06 OneTrust, LLC Privacy management systems and methods
US10803097B2 (en) 2016-06-10 2020-10-13 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10354089B2 (en) 2016-06-10 2019-07-16 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10805354B2 (en) * 2016-06-10 2020-10-13 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10803199B2 (en) 2016-06-10 2020-10-13 OneTrust, LLC Data processing and communications systems and methods for the efficient implementation of privacy by design
US10803198B2 (en) 2016-06-10 2020-10-13 OneTrust, LLC Data processing systems for use in automatically generating, populating, and submitting data subject access requests
US11868507B2 (en) 2016-06-10 2024-01-09 OneTrust, LLC Data processing systems for cookie compliance testing with website scanning and related methods
US10353674B2 (en) 2016-06-10 2019-07-16 OneTrust, LLC Data processing and communications systems and methods for the efficient implementation of privacy by design
US10839102B2 (en) 2016-06-10 2020-11-17 OneTrust, LLC Data processing systems for identifying and modifying processes that are subject to data subject access requests
US10848523B2 (en) 2016-06-10 2020-11-24 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10846261B2 (en) 2016-06-10 2020-11-24 OneTrust, LLC Data processing systems for processing data subject access requests
US10846433B2 (en) 2016-06-10 2020-11-24 OneTrust, LLC Data processing consent management systems and related methods
US10348775B2 (en) 2016-06-10 2019-07-09 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10853501B2 (en) 2016-06-10 2020-12-01 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US10867007B2 (en) 2016-06-10 2020-12-15 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10867072B2 (en) 2016-06-10 2020-12-15 OneTrust, LLC Data processing systems for measuring privacy maturity within an organization
US10873606B2 (en) 2016-06-10 2020-12-22 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10878127B2 (en) 2016-06-10 2020-12-29 OneTrust, LLC Data subject access request processing systems and related methods
US10885485B2 (en) 2016-06-10 2021-01-05 OneTrust, LLC Privacy management systems and methods
US10896394B2 (en) 2016-06-10 2021-01-19 OneTrust, LLC Privacy management systems and methods
US9851966B1 (en) 2016-06-10 2017-12-26 OneTrust, LLC Data processing systems and communications systems and methods for integrating privacy compliance systems with software development and agile tools for privacy design
US10909488B2 (en) 2016-06-10 2021-02-02 OneTrust, LLC Data processing systems for assessing readiness for responding to privacy-related incidents
US10346598B2 (en) 2016-06-10 2019-07-09 OneTrust, LLC Data processing systems for monitoring user system inputs and related methods
US11847182B2 (en) 2016-06-10 2023-12-19 OneTrust, LLC Data processing consent capture systems and related methods
US10909265B2 (en) 2016-06-10 2021-02-02 OneTrust, LLC Application privacy scanning systems and related methods
US10929559B2 (en) 2016-06-10 2021-02-23 OneTrust, LLC Data processing systems for data testing to confirm data deletion and related methods
US10944725B2 (en) 2016-06-10 2021-03-09 OneTrust, LLC Data processing systems and methods for using a data model to select a target data asset in a data migration
US10949567B2 (en) 2016-06-10 2021-03-16 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10949544B2 (en) 2016-06-10 2021-03-16 OneTrust, LLC Data processing systems for data transfer risk identification and related methods
US10949565B2 (en) 2016-06-10 2021-03-16 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10949170B2 (en) 2016-06-10 2021-03-16 OneTrust, LLC Data processing systems for integration of consumer feedback with data subject access requests and related methods
US10346637B2 (en) 2016-06-10 2019-07-09 OneTrust, LLC Data processing systems for the identification and deletion of personal data in computer systems
US9882935B2 (en) 2016-06-10 2018-01-30 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10346638B2 (en) 2016-06-10 2019-07-09 OneTrust, LLC Data processing systems for identifying and modifying processes that are subject to data subject access requests
US10019597B2 (en) 2016-06-10 2018-07-10 OneTrust, LLC Data processing systems and communications systems and methods for integrating privacy compliance systems with software development and agile tools for privacy design
US10970675B2 (en) 2016-06-10 2021-04-06 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10972509B2 (en) 2016-06-10 2021-04-06 OneTrust, LLC Data processing and scanning systems for generating and populating a data inventory
US10970371B2 (en) 2016-06-10 2021-04-06 OneTrust, LLC Consent receipt management systems and related methods
US10984132B2 (en) 2016-06-10 2021-04-20 OneTrust, LLC Data processing systems and methods for populating and maintaining a centralized database of personal data
US10997318B2 (en) 2016-06-10 2021-05-04 OneTrust, LLC Data processing systems for generating and populating a data inventory for processing data access requests
US10997315B2 (en) 2016-06-10 2021-05-04 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10997542B2 (en) 2016-06-10 2021-05-04 OneTrust, LLC Privacy management systems and methods
US10318761B2 (en) 2016-06-10 2019-06-11 OneTrust, LLC Data processing systems and methods for auditing data request compliance
US10289870B2 (en) 2016-06-10 2019-05-14 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US10032172B2 (en) 2016-06-10 2018-07-24 OneTrust, LLC Data processing systems for measuring privacy maturity within an organization
US10102533B2 (en) 2016-06-10 2018-10-16 OneTrust, LLC Data processing and communications systems and methods for the efficient implementation of privacy by design
US11025675B2 (en) 2016-06-10 2021-06-01 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US11023842B2 (en) 2016-06-10 2021-06-01 OneTrust, LLC Data processing systems and methods for bundled privacy policies
US11023616B2 (en) 2016-06-10 2021-06-01 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US10289866B2 (en) 2016-06-10 2019-05-14 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11030563B2 (en) 2016-06-10 2021-06-08 OneTrust, LLC Privacy management systems and methods
US11030274B2 (en) 2016-06-10 2021-06-08 OneTrust, LLC Data processing user interface monitoring systems and related methods
US11030327B2 (en) 2016-06-10 2021-06-08 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11038925B2 (en) 2016-06-10 2021-06-15 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11036882B2 (en) 2016-06-10 2021-06-15 OneTrust, LLC Data processing systems for processing and managing data subject access in a distributed environment
US11036674B2 (en) 2016-06-10 2021-06-15 OneTrust, LLC Data processing systems for processing data subject access requests
US11036771B2 (en) 2016-06-10 2021-06-15 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11057356B2 (en) 2016-06-10 2021-07-06 OneTrust, LLC Automated data processing systems and methods for automatically processing data subject access requests using a chatbot
US11062051B2 (en) 2016-06-10 2021-07-13 OneTrust, LLC Consent receipt management systems and related methods
US11070593B2 (en) 2016-06-10 2021-07-20 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11068618B2 (en) 2016-06-10 2021-07-20 OneTrust, LLC Data processing systems for central consent repository and related methods
US11074367B2 (en) 2016-06-10 2021-07-27 OneTrust, LLC Data processing systems for identity validation for consumer rights requests and related methods
US10282692B2 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US11087260B2 (en) 2016-06-10 2021-08-10 OneTrust, LLC Data processing systems and methods for customizing privacy training
US10282370B1 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11100445B2 (en) 2016-06-10 2021-08-24 OneTrust, LLC Data processing systems for assessing readiness for responding to privacy-related incidents
US11100444B2 (en) 2016-06-10 2021-08-24 OneTrust, LLC Data processing systems and methods for providing training in a vendor procurement process
US10282559B2 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US11113416B2 (en) 2016-06-10 2021-09-07 OneTrust, LLC Application privacy scanning systems and related methods
US10282700B2 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11120162B2 (en) 2016-06-10 2021-09-14 OneTrust, LLC Data processing systems for data testing to confirm data deletion and related methods
US11120161B2 (en) 2016-06-10 2021-09-14 OneTrust, LLC Data subject access request processing systems and related methods
US11122011B2 (en) 2016-06-10 2021-09-14 OneTrust, LLC Data processing systems and methods for using a data model to select a target data asset in a data migration
US11126748B2 (en) 2016-06-10 2021-09-21 OneTrust, LLC Data processing consent management systems and related methods
US11134086B2 (en) 2016-06-10 2021-09-28 OneTrust, LLC Consent conversion optimization systems and related methods
US11138336B2 (en) 2016-06-10 2021-10-05 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10452866B2 (en) 2016-06-10 2019-10-22 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11138318B2 (en) 2016-06-10 2021-10-05 OneTrust, LLC Data processing systems for data transfer risk identification and related methods
US11138242B2 (en) 2016-06-10 2021-10-05 OneTrust, LLC Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software
US11144670B2 (en) 2016-06-10 2021-10-12 OneTrust, LLC Data processing systems for identifying and modifying processes that are subject to data subject access requests
US11144622B2 (en) 2016-06-10 2021-10-12 OneTrust, LLC Privacy management systems and methods
US11727141B2 (en) 2016-06-10 2023-08-15 OneTrust, LLC Data processing systems and methods for synching privacy-related user consent across multiple computing devices
US11146566B2 (en) 2016-06-10 2021-10-12 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11151233B2 (en) 2016-06-10 2021-10-19 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US10284604B2 (en) 2016-06-10 2019-05-07 OneTrust, LLC Data processing and scanning systems for generating and populating a data inventory
US11675929B2 (en) 2016-06-10 2023-06-13 OneTrust, LLC Data processing consent sharing systems and related methods
US11157600B2 (en) 2016-06-10 2021-10-26 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US10275614B2 (en) 2016-06-10 2019-04-30 OneTrust, LLC Data processing systems for generating and populating a data inventory
US10242228B2 (en) 2016-06-10 2019-03-26 OneTrust, LLC Data processing systems for measuring privacy maturity within an organization
US11182501B2 (en) 2016-06-10 2021-11-23 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11188862B2 (en) 2016-06-10 2021-11-30 OneTrust, LLC Privacy management systems and methods
US11188615B2 (en) 2016-06-10 2021-11-30 OneTrust, LLC Data processing consent capture systems and related methods
US11195134B2 (en) 2016-06-10 2021-12-07 OneTrust, LLC Privacy management systems and methods
US11651106B2 (en) 2016-06-10 2023-05-16 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11200341B2 (en) 2016-06-10 2021-12-14 OneTrust, LLC Consent receipt management systems and related methods
US11210420B2 (en) 2016-06-10 2021-12-28 OneTrust, LLC Data subject access request processing systems and related methods
US11222309B2 (en) 2016-06-10 2022-01-11 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11222142B2 (en) 2016-06-10 2022-01-11 OneTrust, LLC Data processing systems for validating authorization for personal data collection, storage, and processing
US11222139B2 (en) 2016-06-10 2022-01-11 OneTrust, LLC Data processing systems and methods for automatic discovery and assessment of mobile software development kits
US11651104B2 (en) 2016-06-10 2023-05-16 OneTrust, LLC Consent receipt management systems and related methods
US11227247B2 (en) 2016-06-10 2022-01-18 OneTrust, LLC Data processing systems and methods for bundled privacy policies
US11228620B2 (en) 2016-06-10 2022-01-18 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10235534B2 (en) 2016-06-10 2019-03-19 OneTrust, LLC Data processing systems for prioritizing data subject access requests for fulfillment and related methods
US11238390B2 (en) 2016-06-10 2022-02-01 OneTrust, LLC Privacy management systems and methods
US11240273B2 (en) 2016-06-10 2022-02-01 OneTrust, LLC Data processing and scanning systems for generating and populating a data inventory
US11244071B2 (en) 2016-06-10 2022-02-08 OneTrust, LLC Data processing systems for use in automatically generating, populating, and submitting data subject access requests
US11244072B2 (en) 2016-06-10 2022-02-08 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US10204154B2 (en) 2016-06-10 2019-02-12 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11256777B2 (en) 2016-06-10 2022-02-22 OneTrust, LLC Data processing user interface monitoring systems and related methods
US11277448B2 (en) 2016-06-10 2022-03-15 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10181051B2 (en) 2016-06-10 2019-01-15 OneTrust, LLC Data processing systems for generating and populating a data inventory for processing data access requests
US11294939B2 (en) 2016-06-10 2022-04-05 OneTrust, LLC Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software
US11295316B2 (en) 2016-06-10 2022-04-05 OneTrust, LLC Data processing systems for identity validation for consumer rights requests and related methods
US11301589B2 (en) 2016-06-10 2022-04-12 OneTrust, LLC Consent receipt management systems and related methods
US11301796B2 (en) 2016-06-10 2022-04-12 OneTrust, LLC Data processing systems and methods for customizing privacy training
US10181019B2 (en) 2016-06-10 2019-01-15 OneTrust, LLC Data processing systems and communications systems and methods for integrating privacy compliance systems with software development and agile tools for privacy design
US11308435B2 (en) 2016-06-10 2022-04-19 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US11328092B2 (en) 2016-06-10 2022-05-10 OneTrust, LLC Data processing systems for processing and managing data subject access in a distributed environment
US11328240B2 (en) 2016-06-10 2022-05-10 OneTrust, LLC Data processing systems for assessing readiness for responding to privacy-related incidents
US11334682B2 (en) 2016-06-10 2022-05-17 OneTrust, LLC Data subject access request processing systems and related methods
US11334681B2 (en) 2016-06-10 2022-05-17 OneTrust, LLC Application privacy scanning systems and related meihods
US11336697B2 (en) 2016-06-10 2022-05-17 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11343284B2 (en) 2016-06-10 2022-05-24 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US11341447B2 (en) 2016-06-10 2022-05-24 OneTrust, LLC Privacy management systems and methods
US11347889B2 (en) 2016-06-10 2022-05-31 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11354434B2 (en) 2016-06-10 2022-06-07 OneTrust, LLC Data processing systems for verification of consent and notice processing and related methods
US11354435B2 (en) 2016-06-10 2022-06-07 OneTrust, LLC Data processing systems for data testing to confirm data deletion and related methods
US11361057B2 (en) 2016-06-10 2022-06-14 OneTrust, LLC Consent receipt management systems and related methods
US11366786B2 (en) 2016-06-10 2022-06-21 OneTrust, LLC Data processing systems for processing data subject access requests
US11366909B2 (en) 2016-06-10 2022-06-21 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11645353B2 (en) 2016-06-10 2023-05-09 OneTrust, LLC Data processing consent capture systems and related methods
US11392720B2 (en) 2016-06-10 2022-07-19 OneTrust, LLC Data processing systems for verification of consent and notice processing and related methods
US11645418B2 (en) 2016-06-10 2023-05-09 OneTrust, LLC Data processing systems for data testing to confirm data deletion and related methods
US11403377B2 (en) 2016-06-10 2022-08-02 OneTrust, LLC Privacy management systems and methods
US11409908B2 (en) 2016-06-10 2022-08-09 OneTrust, LLC Data processing systems and methods for populating and maintaining a centralized database of personal data
US11416590B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11416798B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing systems and methods for providing training in a vendor procurement process
US11416634B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Consent receipt management systems and related methods
US11416636B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing consent management systems and related methods
US11416109B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Automated data processing systems and methods for automatically processing data subject access requests using a chatbot
US11416589B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11418516B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Consent conversion optimization systems and related methods
US11416576B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing consent capture systems and related methods
US11418492B2 (en) 2016-06-10 2022-08-16 OneTrust, LLC Data processing systems and methods for using a data model to select a target data asset in a data migration
US11636171B2 (en) 2016-06-10 2023-04-25 OneTrust, LLC Data processing user interface monitoring systems and related methods
US11438386B2 (en) 2016-06-10 2022-09-06 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10158676B2 (en) 2016-06-10 2018-12-18 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US11625502B2 (en) 2016-06-10 2023-04-11 OneTrust, LLC Data processing systems for identifying and modifying processes that are subject to data subject access requests
US11449633B2 (en) 2016-06-10 2022-09-20 OneTrust, LLC Data processing systems and methods for automatic discovery and assessment of mobile software development kits
US11609939B2 (en) 2016-06-10 2023-03-21 OneTrust, LLC Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software
US11461722B2 (en) 2016-06-10 2022-10-04 OneTrust, LLC Questionnaire response automation for compliance management
US11461500B2 (en) 2016-06-10 2022-10-04 OneTrust, LLC Data processing systems for cookie compliance testing with website scanning and related methods
US11468196B2 (en) 2016-06-10 2022-10-11 OneTrust, LLC Data processing systems for validating authorization for personal data collection, storage, and processing
US11468386B2 (en) 2016-06-10 2022-10-11 OneTrust, LLC Data processing systems and methods for bundled privacy policies
US11586700B2 (en) 2016-06-10 2023-02-21 OneTrust, LLC Data processing systems and methods for automatically blocking the use of tracking tools
US11475136B2 (en) 2016-06-10 2022-10-18 OneTrust, LLC Data processing systems for data transfer risk identification and related methods
US11481710B2 (en) 2016-06-10 2022-10-25 OneTrust, LLC Privacy management systems and methods
US11488085B2 (en) 2016-06-10 2022-11-01 OneTrust, LLC Questionnaire response automation for compliance management
US11586762B2 (en) 2016-06-10 2023-02-21 OneTrust, LLC Data processing systems and methods for auditing data request compliance
US11520928B2 (en) 2016-06-10 2022-12-06 OneTrust, LLC Data processing systems for generating personal data receipts and related methods
US10165011B2 (en) 2016-06-10 2018-12-25 OneTrust, LLC Data processing systems and methods for performing privacy assessments and monitoring of new versions of computer code for privacy compliance
US10169609B1 (en) 2016-06-10 2019-01-01 OneTrust, LLC Data processing systems for fulfilling data subject access requests and related methods
US11562097B2 (en) 2016-06-10 2023-01-24 OneTrust, LLC Data processing systems for central consent repository and related methods
US11544667B2 (en) 2016-06-10 2023-01-03 OneTrust, LLC Data processing systems for generating and populating a data inventory
US11544405B2 (en) 2016-06-10 2023-01-03 OneTrust, LLC Data processing systems for verification of consent and notice processing and related methods
US11558429B2 (en) 2016-06-10 2023-01-17 OneTrust, LLC Data processing and scanning systems for generating and populating a data inventory
US11551174B2 (en) 2016-06-10 2023-01-10 OneTrust, LLC Privacy management systems and methods
US11550897B2 (en) 2016-06-10 2023-01-10 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11556672B2 (en) 2016-06-10 2023-01-17 OneTrust, LLC Data processing systems for verification of consent and notice processing and related methods
US11681733B2 (en) 2017-01-31 2023-06-20 Experian Information Solutions, Inc. Massive scale heterogeneous data ingestion and user resolution
US11227001B2 (en) 2017-01-31 2022-01-18 Experian Information Solutions, Inc. Massive scale heterogeneous data ingestion and user resolution
WO2018170504A1 (en) * 2017-03-17 2018-09-20 Labyrinth Research Llc Unified control of privacy-impacting devices
US9858439B1 (en) 2017-06-16 2018-01-02 OneTrust, LLC Data processing systems for identifying whether cookies contain personally identifying information
US10013577B1 (en) 2017-06-16 2018-07-03 OneTrust, LLC Data processing systems for identifying whether cookies contain personally identifying information
US11663359B2 (en) 2017-06-16 2023-05-30 OneTrust, LLC Data processing systems for identifying whether cookies contain personally identifying information
US11373007B2 (en) 2017-06-16 2022-06-28 OneTrust, LLC Data processing systems for identifying whether cookies contain personally identifying information
US10735183B1 (en) 2017-06-30 2020-08-04 Experian Information Solutions, Inc. Symmetric encryption for private smart contracts among multiple parties in a private peer-to-peer network
US11652607B1 (en) 2017-06-30 2023-05-16 Experian Information Solutions, Inc. Symmetric encryption for private smart contracts among multiple parties in a private peer-to-peer network
US11818282B2 (en) 2017-11-20 2023-11-14 International Business Machines Corporation Non-verbal sensitive data authentication
US11012556B2 (en) * 2017-11-20 2021-05-18 International Business Machines Corporation Non-verbal sensitive data authentication
US11012555B2 (en) 2017-11-20 2021-05-18 International Business Machines Corporation Non-verbal sensitive data authentication
US20190273820A1 (en) * 2017-11-20 2019-09-05 International Business Machines Corporation Non-verbal sensitive data authentication
US10104103B1 (en) 2018-01-19 2018-10-16 OneTrust, LLC Data processing systems for tracking reputational risk via scanning and registry lookup
US10911234B2 (en) 2018-06-22 2021-02-02 Experian Information Solutions, Inc. System and method for a token gateway environment
US11588639B2 (en) 2018-06-22 2023-02-21 Experian Information Solutions, Inc. System and method for a token gateway environment
US20230078396A1 (en) * 2018-09-06 2023-03-16 Linda M. Spulak System and method for the creation, management, and delivery of personal packets of information to be utilized as reverse cookies within network-based environments
US11593523B2 (en) 2018-09-07 2023-02-28 OneTrust, LLC Data processing systems for orphaned data identification and deletion and related methods
US10963591B2 (en) 2018-09-07 2021-03-30 OneTrust, LLC Data processing systems for orphaned data identification and deletion and related methods
US11947708B2 (en) 2018-09-07 2024-04-02 OneTrust, LLC Data processing systems and methods for automatically protecting sensitive data within privacy management systems
US10803202B2 (en) 2018-09-07 2020-10-13 OneTrust, LLC Data processing systems for orphaned data identification and deletion and related methods
US11734234B1 (en) 2018-09-07 2023-08-22 Experian Information Solutions, Inc. Data architecture for supporting multiple search models
US10963434B1 (en) 2018-09-07 2021-03-30 Experian Information Solutions, Inc. Data architecture for supporting multiple search models
US11544409B2 (en) 2018-09-07 2023-01-03 OneTrust, LLC Data processing systems and methods for automatically protecting sensitive data within privacy management systems
US11157654B2 (en) 2018-09-07 2021-10-26 OneTrust, LLC Data processing systems for orphaned data identification and deletion and related methods
US11144675B2 (en) 2018-09-07 2021-10-12 OneTrust, LLC Data processing systems and methods for automatically protecting sensitive data within privacy management systems
US11620403B2 (en) 2019-01-11 2023-04-04 Experian Information Solutions, Inc. Systems and methods for secure data aggregation and computation
US11924191B2 (en) 2019-07-23 2024-03-05 Allstate Insurance Company Safe logon
US11196734B2 (en) 2019-07-23 2021-12-07 Allstate Insurance Company Safe logon
EP4004772A4 (en) * 2019-07-23 2023-08-23 Allstate Insurance Company Safe logon
WO2021015957A1 (en) 2019-07-23 2021-01-28 Allstate Insurance Company Safe logon
US11941065B1 (en) 2019-09-13 2024-03-26 Experian Information Solutions, Inc. Single identifier platform for storing entity data
US11449797B1 (en) 2019-09-23 2022-09-20 Amazon Technologies, Inc. Secure machine learning workflow automation using isolated resources
US11797528B2 (en) 2020-07-08 2023-10-24 OneTrust, LLC Systems and methods for targeted data discovery
US11444976B2 (en) 2020-07-28 2022-09-13 OneTrust, LLC Systems and methods for automatically blocking the use of tracking tools
US11475165B2 (en) 2020-08-06 2022-10-18 OneTrust, LLC Data processing systems and methods for automatically redacting unstructured data from a data subject access request
US11704440B2 (en) 2020-09-15 2023-07-18 OneTrust, LLC Data processing systems and methods for preventing execution of an action documenting a consent rejection
US11436373B2 (en) 2020-09-15 2022-09-06 OneTrust, LLC Data processing systems and methods for detecting tools for the automatic blocking of consent requests
US11526624B2 (en) 2020-09-21 2022-12-13 OneTrust, LLC Data processing systems and methods for automatically detecting target data transfers and target data processing
US11954225B1 (en) 2020-11-02 2024-04-09 Wells Fargo Bank, N.A. Data privacy management
US11615192B2 (en) 2020-11-06 2023-03-28 OneTrust, LLC Systems and methods for identifying data processing activities based on data discovery results
US11397819B2 (en) 2020-11-06 2022-07-26 OneTrust, LLC Systems and methods for identifying data processing activities based on data discovery results
US11687528B2 (en) 2021-01-25 2023-06-27 OneTrust, LLC Systems and methods for discovery, classification, and indexing of data in a native computing system
US11442906B2 (en) 2021-02-04 2022-09-13 OneTrust, LLC Managing custom attributes for domain objects defined within microservices
US11494515B2 (en) 2021-02-08 2022-11-08 OneTrust, LLC Data processing systems and methods for anonymizing data samples in classification analysis
US11601464B2 (en) 2021-02-10 2023-03-07 OneTrust, LLC Systems and methods for mitigating risks of third-party computing system functionality integration into a first-party computing system
US11775348B2 (en) 2021-02-17 2023-10-03 OneTrust, LLC Managing custom workflows for domain objects defined within microservices
US11546661B2 (en) 2021-02-18 2023-01-03 OneTrust, LLC Selective redaction of media content
US11533315B2 (en) 2021-03-08 2022-12-20 OneTrust, LLC Data transfer discovery and analysis systems and related methods
US11880377B1 (en) 2021-03-26 2024-01-23 Experian Information Solutions, Inc. Systems and methods for entity resolution
US11816224B2 (en) 2021-04-16 2023-11-14 OneTrust, LLC Assessing and managing computational risk involved with integrating third party computing functionality within a computing system
US11562078B2 (en) 2021-04-16 2023-01-24 OneTrust, LLC Assessing and managing computational risk involved with integrating third party computing functionality within a computing system
US11620142B1 (en) 2022-06-03 2023-04-04 OneTrust, LLC Generating and customizing user interfaces for demonstrating functions of interactive user environments
US11968229B2 (en) 2022-09-12 2024-04-23 OneTrust, LLC Systems and methods for automatically blocking the use of tracking tools
US11960564B2 (en) 2023-02-02 2024-04-16 OneTrust, LLC Data processing systems and methods for automatically blocking the use of tracking tools
US11962681B2 (en) 2023-04-04 2024-04-16 Experian Information Solutions, Inc. Symmetric encryption for private smart contracts among multiple parties in a private peer-to-peer network

Also Published As

Publication number Publication date
US20030088520A1 (en) 2003-05-08

Similar Documents

Publication Publication Date Title
US7478157B2 (en) System, method, and business methods for enforcing privacy preferences on personal-data exchanges across a network
CA2568096C (en) Networked identity framework
US9058471B2 (en) Authorization system for heterogeneous enterprise environments
US20200162478A1 (en) Methods and Systems for Virtual File Storage and Encryption
US20040073668A1 (en) Policy delegation for access control
US7305432B2 (en) Privacy preferences roaming and enforcement
Hu et al. Dynamic, context-aware access control for distributed healthcare applications
US7356840B1 (en) Method and system for implementing security filters for reporting systems
US7478407B2 (en) Supporting multiple application program interfaces
US20100299738A1 (en) Claims-based authorization at an identity provider
US20020143961A1 (en) Access control protocol for user profile management
US20020174238A1 (en) Employing electronic certificate workflows
US20040267749A1 (en) Resource name interface for managing policy resources
WO2007120754A2 (en) Relationship-based authorization
EP2186254A2 (en) Transferable restricted security tokens
CN104255007A (en) Oauth framework
WO2003107224A1 (en) Assignment and management of authentication &amp; authorization
CN113574528A (en) Providing policy-compliant storage for DID data
US20050005174A1 (en) Configurable password authentication policies
Dubey et al. Crowd review and attribute-based credit computation for an access control mechanism in cloud data centers
Schläger et al. Attribute-based authentication and authorisation infrastructures for e-commerce providers
Dai et al. UDDI access control
WO2001075724A1 (en) Persona data structure and system for managing and distributing privacy-controlled data
Nur et al. Identity relationship management for Internet of Things: A case study
WO2021055989A1 (en) Distributed attribute based access control as means of data protection and collaboration in sensitive (personal) digital record and activity trail investigations

Legal Events

Date Code Title Description
AS Assignment

Owner name: INTERNATIONAL BUSINESS MACHINES CORPORATION, NEW Y

Free format text: ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNORS:BOHRER, KATHRYN A.;CHESS, CATHERINE A.;HOCH, ROBERT L.;AND OTHERS;REEL/FRAME:012499/0081;SIGNING DATES FROM 20011022 TO 20011031

FEPP Fee payment procedure

Free format text: PAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY

STCF Information on status: patent grant

Free format text: PATENTED CASE

FPAY Fee payment

Year of fee payment: 4

FPAY Fee payment

Year of fee payment: 8

FEPP Fee payment procedure

Free format text: MAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY

FEPP Fee payment procedure

Free format text: 11.5 YR SURCHARGE- LATE PMT W/IN 6 MO, LARGE ENTITY (ORIGINAL EVENT CODE: M1556); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY

MAFP Maintenance fee payment

Free format text: PAYMENT OF MAINTENANCE FEE, 12TH YEAR, LARGE ENTITY (ORIGINAL EVENT CODE: M1553); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY

Year of fee payment: 12